CVE-2026-69686
massStack Buffer Overflow RCE in Microsoft Word (Office 2019/2021/2024, Microsoft 365 Apps)
CVE-2026-69686 is a stack-based buffer overflow (CWE-121) in the Microsoft Word component of Office that allows an unauthorized attacker to execute arbitrary code over a network. The CVSS vector requires user interaction (UI:R) with no authentication or privileges, consistent with an attacker persuading a user to open a maliciously crafted document, which overflows a stack buffer and runs attacker-controlled code. Successful exploitation yields code execution with the privileges of the current user, with high impact on confidentiality, integrity, and availability. Any user of Microsoft 365 Apps, Microsoft 365, or the perpetual Office 2019, Office 2021, and Office 2024 editions of Word is potentially affected. There is no known in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates a 0.8% probability of exploitation within 30 days (55th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69686 via Microsoft Update or the Microsoft 365 Apps update channel to all Microsoft 365 Apps and Office 2019/2021/2024 installations, and verify deployed build numbers against the vendor advisory since specific patched versions are not listed in the source data. Until patching is complete, keep Office Protected View enabled and caution users against opening documents from untrusted sources, as exploitation requires user interaction. Inventory which Office editions and channels are in use and prioritize endpoints that routinely handle untrusted files.
| microsoft 365 Apps (Microsoft 365 Apps) | — |
| Microsoft 365 | — |
| microsoft Office 2019 (Word component) | — |
| microsoft Office 2021 (Word component) | — |
| microsoft Office 2024 (Word component) | — |
| microsoft Word | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.