CVE-2026-69614
massStack Buffer Overflow in Microsoft Office Access Allows Remote Code Execution
Microsoft Office Access contains a stack-based buffer overflow (CWE-121) resulting from improper input validation (CWE-20) that allows an unauthorized attacker to execute code over a network. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates no privileges are required but user interaction is, most plausibly by persuading a user to open a maliciously crafted Access database delivered via email, a download, or a network share. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability, typically in the context of the user who opened the file. Any organization or individual running Microsoft Office with Access installed is potentially affected. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.9% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69614 via your standard Office/Microsoft 365 update channel or the Microsoft Update Catalog, and confirm coverage for your specific Office release in Microsoft's advisory since fixed versions are not listed in this data. Until patched, warn users not to open Access database files (e.g., .accdb) from untrusted senders or untrusted network locations, as user interaction is the required trigger. Inventory which endpoints have Access installed to prioritize patching and improve future exposure assessments.
| Microsoft Office Access (Microsoft Access, the database component of Microsoft Office/Microsoft 365) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, access, office 2019, office 2021, office 2024
- Weakness
- CWE-20, CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.