VYPR
Vypr IntelligenceAI-generatedSep 8, 2026· 25 CVEs

Microsoft Office Excel: 25 Vulnerabilities Disclosed in Single September 2026 Batch

Microsoft Office Excel faces a batch of 25 vulnerabilities disclosed on September 8, 2026, including high-severity flaws allowing code execution.

Key findings

  • 25 vulnerabilities in Microsoft Office Excel disclosed on September 8, 2026.
  • Flaws include heap overflows, out-of-bounds reads, and use-after-free, enabling code execution.
  • Medium severity vulnerabilities allow for local information disclosure.
  • While no Excel-specific zero-days were reported exploited, the batch is part of a large security update.
  • Users should prioritize applying Microsoft's security patches for Office Excel.

On September 8, 2026, Microsoft released a massive security update addressing 25 vulnerabilities in Microsoft Office Excel. This batch of CVEs, disclosed simultaneously, includes a mix of high and medium severity flaws, with several allowing for remote code execution and information disclosure. The vulnerabilities stem from common programming errors such as buffer overflows, out-of-bounds reads, use-after-free, double free, and type confusion.

The disclosed vulnerabilities can be broadly categorized by their impact:

Remote Code Execution

A significant portion of the batch, including several high-severity flaws, permits attackers to execute code remotely. These include:

Information Disclosure

Other vulnerabilities, generally rated medium severity, allow attackers to disclose sensitive information locally. These include:

Exploitation and Response

While the provided CVE details do not explicitly state that these specific Excel vulnerabilities were exploited in the wild, related security reporting from September 2026 indicates that Microsoft addressed two zero-day vulnerabilities that were actively exploited. These specific zero-days were related to Windows ALPC and Windows Update Stack, not directly to Office Excel. However, the sheer volume of vulnerabilities patched in this batch underscores the ongoing threat landscape for Microsoft products. Users are strongly advised to apply the latest security updates from Microsoft to mitigate these risks. Specific version information for affected and patched versions was not detailed in the provided CVE descriptions, but it is standard practice for Microsoft to release cumulative updates that address such vulnerabilities.

This coordinated disclosure of 25 vulnerabilities in Microsoft Office Excel highlights the critical need for prompt patching and security diligence. Users should prioritize updating their Office installations to ensure protection against potential exploitation of these flaws, which could lead to code execution or sensitive data exposure. The breadth of vulnerability types suggests a need for robust security practices and regular security audits of software.

AI-written article. Grounded in 25 CVE records listed below.