CVE-2026-69529
massHeap-Based Buffer Overflow in Microsoft Access Allows Remote Code Execution
CVE-2026-69529 is a heap-based buffer overflow (CWE-122) in Microsoft Access, the database component of Microsoft Office/Microsoft 365, which Microsoft rates as remotely exploitable with no privileges required (CVSS 8.8). The CVSS vector requires user interaction (UI:R), indicating the victim must be induced to open or process attacker-supplied content in Access rather than the flaw being reachable from a headless service. Successful exploitation yields arbitrary code execution running with the victim user's privileges, with high impact on confidentiality, integrity, and availability (S:U, C:H/I:H/A:H). Any organization running an affected Microsoft Office/Microsoft 365 build that includes Access is potentially affected. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.6% probability of exploitation within 30 days (45th percentile).
What to do: Check installed Office/Access versions against the affected-products table in the Microsoft MSRC advisory and apply the vendor security update that fixes CVE-2026-69529 as soon as it is available. Until patched, caution users against opening unsolicited database files or other attacker-supplied content in Access, since user interaction is required for exploitation. Note that no in-the-wild exploitation or public PoC is known, but Microsoft RCE flaws of this class are typically exploited quickly once details circulate, so treat patching as a priority.
| Microsoft Access (component of Microsoft Office / Microsoft 365) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, access, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.