AI analysis
CVE-2026-69632 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Office that an unauthorized attacker can trigger over a network to execute arbitrary code. The network attack vector requires user interaction (the CVSS vector includes UI:R), meaning a victim typically must open a malicious Office document or click a crafted link for the bug to be reached, and no privileges are required. Successful exploitation yields code execution in the context of the Office user, with high impact on the confidentiality, integrity, and availability of the endpoint. Any organization or individual running affected Microsoft Office builds is potentially affected, though current exploitation risk is low: there is no known in-the-wild exploitation, no public proof-of-concept, no CISA KEV listing, and EPSS assigns only a 0.8% probability of exploitation within 30 days. Microsoft addressed the issue in its September 2026 Patch Tuesday security updates.
What to do: Apply Microsoft's September 2026 Patch Tuesday security updates for Office as soon as feasible and verify installed Office build numbers against Microsoft's advisory, since the affected version list is not enumerated in this data. As interim mitigation, discourage opening unsolicited Office documents and links, and apply attack-surface-reduction controls (e.g., blocking macros/files from untrusted sources). Monitor for KEV addition, public PoC emergence, or EPSS movement to reprioritize this fix within your Patch Tuesday backlog.
Estimated exposure
masshundreds of millions of users (Office runs on an estimated ~1 billion Windows/enterprise devices worldwide) — Exact affected build ranges are not listed, but Microsoft Office is the dominant desktop productivity suite across enterprise and consumer Windows fleets, so the plausible exposed population is on the order of hundreds of millions of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.