CVE-2026-81401

Summary

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft 365 Apps for Enterprise16.0.1 < 16.0.20326.20138affected
MicrosoftMicrosoft Excel 201616.0.0.0 < 16.0.5569.1003affected
MicrosoftMicrosoft Office 201616.0.0 < 16.0.5569.1003affected
MicrosoftMicrosoft Office 201919.0.0 < 16.0.10417.20207affected
MicrosoftMicrosoft Office 365 for Mac-affected
MicrosoftMicrosoft Office LTSC 202116.0.1 < 16.0.14334.20906affected
MicrosoftMicrosoft Office LTSC 202416.0.0 < 16.0.17932.20976affected
MicrosoftMicrosoft Office LTSC for Mac 2021-affected
MicrosoftMicrosoft Office LTSC for Mac 2024-affected
MicrosoftOffice Online Server16.0.0.0 < 16.0.10417.20207affected

Weaknesses

  • CWE-843: CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References