Microsoft Security Response Center documentation identifies the issue as a heap-based buffer overflow in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. The vulnerability is tracked as CWE-122, the Common Weakness Enumeration category for heap-based buffer overflow flaws.
CVE-2026-81951 affects Excel through malicious Office files
CVE-2026-81951 carries a Critical severity rating and a CVSS base score of 7.8. Its temporal score is 6.8, using the vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C.
The scoring describes an attack that is local to the affected application, has low attack complexity, requires no privileges, and requires user interaction. In Microsoft’s account of the required interaction, an attacker must send a user a malicious Office file and convince them to open it.
The result is potentially serious: a successful exploit allows local code execution, with the CVSS vector assigning high impacts to confidentiality, integrity, and availability. For administrators, the relevant exposure is therefore the familiar document-delivery path: users receiving and opening untrusted Office files on installations that have not received the applicable security update.
Microsoft specifically says the Preview Pane is not an attack vector for this vulnerability. The stated trigger is opening the malicious Office file, so organizations should focus their immediate response on patch deployment and on reinforcing normal caution around unsolicited or unexpected documents.
Publicly disclosed: No
Exploited: No
Customer action required: Yes
Microsoft’s exploitation assessment is Exploitation Less Likely. That assessment helps prioritize response, but it does not change the vendor’s requirement to install the available fixes across affected product lines.
Microsoft 365 Apps and perpetual Office releases use different CVE-2026-81951 fix paths
The operational detail in this advisory is that the same Excel vulnerability spans subscription builds, perpetual Windows releases, and Mac releases. There is no single Windows KB that covers every listed product. Administrators need to map each deployed Office family and architecture to its stated remediation target.
For Microsoft 365 Apps for Enterprise for 32-bit Systems (x86), update to fixed build 16.0.20326.20138 or later.
For Microsoft 365 Apps for Enterprise for 64-bit Systems (x64), update to fixed build 16.0.20326.20138 or later.
For Microsoft Excel 2016 (32-bit edition) (x86), install KB5002914 to reach fixed build 16.0.5569.1003.
For Microsoft Excel 2016 (64-bit edition) (x64), install KB5002914 to reach fixed build 16.0.5569.1003.
For Microsoft Office 2016 (32-bit edition) (x86), install KB5002904 to reach fixed build 16.0.5569.1003.
For Microsoft Office 2016 (64-bit edition) (x64), install KB5002904 to reach fixed build 16.0.5569.1003.
The distinction between Excel 2016 and Office 2016 is consequential for patch management. Excel-only installations are mapped to KB5002914, while the Office 2016 product entries are mapped to KB5002904, though both reach fixed build 16.0.5569.1003. Deployment teams should match the update to the installed product rather than treating the shared build number as permission to substitute packages.
For Microsoft Office 2019 for 32-bit editions (x86), update to fixed build 16.0.10417.20207 or later.
For Microsoft Office 2019 for 64-bit editions (x64), update to fixed build 16.0.10417.20207 or later.
For Microsoft Office LTSC 2021 for 32-bit editions (x86), update to fixed build 16.0.14334.20906 or later.
For Microsoft Office LTSC 2021 for 64-bit editions (x64), update to fixed build 16.0.14334.20906 or later.
For Microsoft Office LTSC 2024 for 32-bit editions (x86), update to fixed build 16.0.17932.20976 or later.
For Microsoft Office LTSC 2024 for 64-bit editions (x64), update to fixed build 16.0.17932.20976 or later.
Office for Mac has a shared CVE-2026-81951 fixed build
Mac administrators have a simpler fixed-version target across the affected releases, but should still identify whether devices run Microsoft Office 365 for Mac or either LTSC edition.
For Microsoft Office 365 for Mac, update to fixed build 16.113.26091433 or later.
For Microsoft Office LTSC for Mac 2021, update to fixed build 16.113.26091433 or later.
For Microsoft Office LTSC for Mac 2024, update to fixed build 16.113.26091433 or later.
Microsoft states that, as of September 16, 2026, the security update for Microsoft Office LTSC for Mac 2021, 2024 and Microsoft Office 365 for Mac is available. Customers running Microsoft Office LTSC for Mac 2021, 2024 and Microsoft Office 365 for Mac should ensure the update is installed to be protected from this vulnerability.
What this means for you
Treat CVE-2026-81951 as a targeted Office update-verification task: identify the Office product family and architecture in use, then confirm that it has reached Microsoft’s exact fixed build or installed the matching KB. The advisory’s user-interaction requirement and less-likely exploitation assessment can guide short-term risk triage, but Microsoft has marked customer action as required.
- Microsoft 365 Apps for Enterprise for 32-bit Systems (x86) and Microsoft 365 Apps for Enterprise for 64-bit Systems (x64) require fixed build 16.0.20326.20138 or later.
- Microsoft Excel 2016 (32-bit edition) (x86) and Microsoft Excel 2016 (64-bit edition) (x64) require KB5002914 and fixed build 16.0.5569.1003.
- Microsoft Office 2016 (32-bit edition) (x86) and Microsoft Office 2016 (64-bit edition) (x64) require KB5002904 and fixed build 16.0.5569.1003.
- Microsoft Office 2019 for 32-bit editions (x86) and Microsoft Office 2019 for 64-bit editions (x64) require fixed build 16.0.10417.20207 or later, while Office LTSC 2021 requires 16.0.14334.20906 or later and Office LTSC 2024 requires 16.0.17932.20976 or later.
- Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 require fixed build 16.113.26091433 or later.
- The Preview Pane is not an attack vector; the documented attack path requires an attacker to persuade a user to open a malicious Office file.
CVE-2026-81951 is a document-triggered Excel code-execution issue with a clear vendor remediation path across current and older Office branches. The sensible response is to make fixed-build verification part of the next Office update compliance cycle, with particular attention to installations still managed through Office 2016-specific KB packages and Mac fleets that need build 16.113.26091433 or later.