CVE-2026-69671
massHeap-Based Buffer Overflow RCE in Microsoft Word (Microsoft 365 and Office suites)
CVE-2026-69671 is a heap-based buffer overflow (CWE-122) in Microsoft Word, the word-processing component of Microsoft 365 Apps, Microsoft 365, and the Office 2019, 2021, and 2024 suites. Per the CVSS vector, a remote, unauthenticated attacker can reach the flaw over a network but must induce user interaction, which in practice means corrupting Word's memory when a victim opens attacker-supplied content such as a crafted document. Successful exploitation yields arbitrary code execution in the context of the user running Word, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.8, High). Any user or organization running the affected Word/Office editions is exposed; the available data does not specify affected build or version ranges, so consult Microsoft's advisory for details. Exploitation has not yet been observed: there is no known public proof-of-concept, the CVE is not in CISA KEV, and EPSS currently assigns a 0.8% probability of exploitation within 30 days (55th percentile).
What to do: Apply the Microsoft security update for CVE-2026-69671 to all affected Office installations as soon as it is available through your update channel (Windows Update/Microsoft AutoUpdate or the Microsoft Update Catalog), and verify installed Word builds against Microsoft's advisory, since affected version ranges were not specified in the available data. Until patched, discourage opening untrusted documents and consider hardening such as disabling the Outlook/Explorer preview pane and filtering risky attachment types. Given the 8.8 severity and network-reachable code execution, treat this as a high-priority patch even though no in-the-wild exploitation or public PoC is currently known.
| Microsoft 365 Apps (Word component) | — |
| Microsoft 365 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
| microsoft Word | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.