VDB
CVE-2026-81394
CVE-2026-81394
PUBLISHED
CVSS 5.5 MEDIUM
Reported by microsoft · Published September 8, 2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1 |
| Microsoft | Microsoft Excel 2016 | 16.0.0.0 |
| Microsoft | Microsoft Office 2016 | 16.0.0 |
| Microsoft | Microsoft Office 2019 | 19.0.0 |
| Microsoft | Microsoft Office 365 for Mac | - |
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1 |
| Microsoft | Microsoft Office LTSC 2024 | 16.0.0 |
| Microsoft | Microsoft Office LTSC for Mac 2021 | - |
| Microsoft | Microsoft Office LTSC for Mac 2024 | - |
| Microsoft | Microsoft Excel 2016 | 16.0.0.0 |
| microsoft | office_365 | - |
| Microsoft | Microsoft Office 2019 | 19.0.0 |
| microsoft | office_2024 | 16.0.0 |
| microsoft | office_2016 | 16.0.0 |
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1 |
| Microsoft | Microsoft Office 2016 | 16.0.0 |
| microsoft | office_2019 | 19.0.0 |
| microsoft | office_macos_2021 | - |
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1 |
| microsoft | 365_apps | 16.0.1 |
…and 7 more
Timeline
- Sep 8, 2026 Coalition ESS Score
- Sep 8, 2026 CVE Published
- Sep 8, 2026 CVE Updated
- Sep 9, 2026 Security Advisory
References
- Microsoft Excel Information Disclosure Vulnerability vendor-advisorypatch