CVE-2026-81954
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 0.32%
- CWE
- CWE-416
- Published
- 2026-09-08
- Last modified
- 2026-09-11
Affected products
- Microsoft Microsoft 365 Apps for Enterprise
- Microsoft Microsoft Excel 2016
- Microsoft Microsoft Office 2016
- Microsoft Microsoft Office 2019
- Microsoft Microsoft Office 365 for Mac
- Microsoft Microsoft Office LTSC 2021
- Microsoft Microsoft Office LTSC 2024
- Microsoft Microsoft Office LTSC for Mac 2021
Weakness type
Related vulnerabilities
- CVE-2026-78133 — libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision...
- CVE-2026-45752 — Suricata detect/transform: use-after-free in decompress transforms
- CVE-2026-45751 — Suricata detect/transform: use-after-free in dotprefix transform
- CVE-2026-88032 — Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver
- CVE-2026-87933 — DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free
- CVE-2026-87877 — zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free via Setters Called After close()
- CVE-2026-87825 — zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free of Compression and Decompression Dictionaries
- CVE-2026-87617 — Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...