ZeroHour

CVE-2026-69678

mass

Use-After-Free RCE in Microsoft PowerPoint (Microsoft 365 Apps / Office)

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69678 is a use-after-free memory-corruption flaw (CWE-416) in Microsoft Office PowerPoint. An unauthenticated remote attacker can trigger it by persuading a user to open a specially crafted PowerPoint file, consistent with the network attack vector and user-interaction requirement in the CVSS vector; no privileges are needed. Successful exploitation allows the attacker to execute arbitrary code in the context of the logged-in user, with high impact on confidentiality, integrity, and availability. The flaw affects the PowerPoint component in Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2019, Office 2021, and Office 2024 releases. As of the September 2026 Patch Tuesday review, there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS assigns a 0.8% 30-day exploitation probability, so no exploitation is currently known.

What to do: Apply Microsoft's September 2026 security updates to Microsoft 365 Apps and the supported Office 2019/2021/2024 releases as soon as practicable, prioritizing workstations that routinely handle untrusted presentations. Until patched, exercise caution with PowerPoint files from untrusted senders, since exploitation requires a user to open the file. Verify remediation by confirming the installed PowerPoint build matches the fixed version listed in Microsoft's advisory.

Affected
Microsoft 365 Apps (PowerPoint component)
Microsoft 365 (PowerPoint component)
Microsoft Office 2019 (PowerPoint component)
Microsoft Office 2021 (PowerPoint component)
Microsoft Office 2024 (PowerPoint component)
Microsoft PowerPoint (standalone/office-suite component)
Estimated exposure
masshundreds of millions of users/devices (Microsoft 365 alone is reported at roughly 400 million commercial seats, plus perpetual Office installs) — Office/PowerPoint is near-ubiquitous on enterprise and consumer Windows desktops, and Microsoft's reported Microsoft 365 seat counts (~400M) plus perpetual Office 2019/2021/2024 deployments put the potentially vulnerable installed base in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, powerpoint
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.