CVE-2026-69285
massHeap-Based Buffer Overflow RCE in Microsoft Office and Microsoft 365 Apps
CVE-2026-69285 is a heap-based buffer overflow (CWE-122) in Microsoft Office that an unauthorized attacker can exploit over a network to execute arbitrary code. Per the CVSS vector (AV:N/PR:N/UI:R), exploitation requires no privileges or special conditions but does require user interaction, which typically means the victim must open or interact with attacker-supplied content such as a crafted document. A successful attack would let the attacker run code with the victim user's privileges, with high impact on confidentiality, integrity, and availability. Affected products include Microsoft 365 Apps and the perpetual editions Office 2016, Office 2019, Office 2021, and Office 2024. There is currently no public proof-of-concept, the flaw is not listed in CISA's KEV, and EPSS estimates only a 0.6% chance of exploitation within 30 days, so there is no confirmed in-the-wild exploitation yet.
What to do: Track Microsoft's advisory for CVE-2026-69285 and apply the released Office security updates to Microsoft 365 Apps and Office 2016/2019/2021/2024 as soon as they are available, confirming all workstation Office builds are fully patched. Until patched, discourage users from opening untrusted Office documents and attachments, since exploitation requires user interaction. With no public PoC or known exploitation and a low EPSS score, a prompt-but-standard patch cadence is reasonable, but monitor for new exploit releases given heap-overflow RCEs in Office are commonly weaponized.
| Microsoft 365 Apps | — |
| Microsoft Office 2016 | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.