Microsoft Office Excel: 25 Vulnerabilities Disclosed in Single September 2026 Batch
Key findings • 25 vulnerabilities in Microsoft Office Excel disclosed on September 8, 2026. • Flaws include heap overflows, out-of-bounds reads, and use-after-free, enabling code execution. …

Key findings
- 25 vulnerabilities in Microsoft Office Excel disclosed on September 8, 2026.
- Flaws include heap overflows, out-of-bounds reads, and use-after-free, enabling code execution.
- Medium severity vulnerabilities allow for local information disclosure.
- While no Excel-specific zero-days were reported exploited, the batch is part of a large security update.
- Users should prioritize applying Microsoft's security patches for Office Excel.
On September 8, 2026, Microsoft released a massive security update addressing 25 vulnerabilities in Microsoft Office Excel. This batch of CVEs, disclosed simultaneously, includes a mix of high and medium severity flaws, with several allowing for remote code execution and information disclosure. The vulnerabilities stem from common programming errors such as buffer overflows, out-of-bounds reads, use-after-free, double free, and type confusion.
The disclosed vulnerabilities can be broadly categorized by their impact:
Remote Code Execution
A significant portion of the batch, including several high-severity flaws, permits attackers to execute code remotely. These include:
- Heap-based buffer overflows: CVE-2026-81960, CVE-2026-81959, CVE-2026-81398, CVE-2026-81397.
- Out-of-bounds reads leading to code execution: CVE-2026-81957, CVE-2026-81956.
- Use-after-free: CVE-2026-81954.
- Stack-based buffer overflows: CVE-2026-81953, CVE-2026-81396.
- Double free: CVE-2026-81950.
- Integer overflow or wraparound: CVE-2026-81949.
Information Disclosure
Other vulnerabilities, generally rated medium severity, allow attackers to disclose sensitive information locally. These include:
- Out-of-bounds reads: CVE-2026-85875, CVE-2026-81400, CVE-2026-81395, CVE-2026-81393, CVE-2026-81392, CVE-2026-81390.
- Buffer over-reads: CVE-2026-81399.
- Use of uninitialized resources: CVE-2026-81958, CVE-2026-81391.
- Access of resource using incompatible type ('type confusion'): CVE-2026-81401.
- Exposure of sensitive system information: CVE-2026-81394.
Exploitation and Response
While the provided CVE details do not explicitly state that these specific Excel vulnerabilities were exploited in the wild, related security reporting from September 2026 indicates that Microsoft addressed two zero-day vulnerabilities that were actively exploited. These specific zero-days were related to Windows ALPC and Windows Update Stack, not directly to Office Excel. However, the sheer volume of vulnerabilities patched in this batch underscores the ongoing threat landscape for Microsoft products. Users are strongly advised to apply the latest security updates from Microsoft to mitigate these risks. Specific version information for affected and patched versions was not detailed in the provided CVE descriptions, but it is standard practice for Microsoft to release cumulative updates that address such vulnerabilities.
This coordinated disclosure of 25 vulnerabilities in Microsoft Office Excel highlights the critical need for prompt patching and security diligence. Users should prioritize updating their Office installations to ensure protection against potential exploitation of these flaws, which could lead to code execution or sensitive data exposure. The breadth of vulnerability types suggests a need for robust security practices and regular security audits of software.