AI analysis
CVE-2026-69678 is a use-after-free memory-corruption flaw (CWE-416) in Microsoft Office PowerPoint. An unauthenticated remote attacker can trigger it by persuading a user to open a specially crafted PowerPoint file, consistent with the network attack vector and user-interaction requirement in the CVSS vector; no privileges are needed. Successful exploitation allows the attacker to execute arbitrary code in the context of the logged-in user, with high impact on confidentiality, integrity, and availability. The flaw affects the PowerPoint component in Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2019, Office 2021, and Office 2024 releases. As of the September 2026 Patch Tuesday review, there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS assigns a 0.8% 30-day exploitation probability, so no exploitation is currently known.
What to do: Apply Microsoft's September 2026 security updates to Microsoft 365 Apps and the supported Office 2019/2021/2024 releases as soon as practicable, prioritizing workstations that routinely handle untrusted presentations. Until patched, exercise caution with PowerPoint files from untrusted senders, since exploitation requires a user to open the file. Verify remediation by confirming the installed PowerPoint build matches the fixed version listed in Microsoft's advisory.
Affected
| Microsoft 365 Apps (PowerPoint component) | — |
| Microsoft 365 (PowerPoint component) | — |
| Microsoft Office 2019 (PowerPoint component) | — |
| Microsoft Office 2021 (PowerPoint component) | — |
| Microsoft Office 2024 (PowerPoint component) | — |
| Microsoft PowerPoint (standalone/office-suite component) | — |
Estimated exposure
masshundreds of millions of users/devices (Microsoft 365 alone is reported at roughly 400 million commercial seats, plus perpetual Office installs) — Office/PowerPoint is near-ubiquitous on enterprise and consumer Windows desktops, and Microsoft's reported Microsoft 365 seat counts (~400M) plus perpetual Office 2019/2021/2024 deployments put the potentially vulnerable installed base in…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.