CVE-2026-81394: Microsoft 365 Apps
Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Affected products
- Microsoft 365 Apps: affected versions not specified
- Microsoft Excel: version 2016 only
- Microsoft Microsoft 365: affected versions not specified
- Microsoft Office 2016: affected versions not specified
- Microsoft Office 2019: affected versions not specified
- Microsoft Office 2021: affected versions not specified
- Microsoft Office 2024: affected versions not specified
Published 2026-09-08. Last modified 2026-09-17.