CVE-2026-69722
massStack-based buffer overflow in Microsoft Word enables remote code execution
CVE-2026-69722 is a stack-based buffer overflow (CWE-121) in the Word component of Microsoft Office that allows an unauthorized attacker to execute code over a network. The CVSS vector (AV:N, PR:N, UI:R) indicates the attack requires no authentication or special privileges but does require user interaction, consistent with an attacker persuading a user to open a maliciously crafted Word document; the exact trigger is not detailed in the available data. Successful exploitation would yield code execution in the context of the user running Word, with high impact on confidentiality, integrity, and availability. Affected products include Microsoft 365 Apps/Microsoft 365 and the perpetual Office 2019, 2021, and 2024 suites, meaning effectively any supported Office installation containing Word is exposed; specific build ranges were not provided in the source data. As of this analysis there is no known in-the-wild exploitation, no CISA KEV listing, and no public proof-of-concept, with EPSS estimating a 0.8% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69722 to Word in all affected products (Microsoft 365 Apps, Office 2019, 2021, and 2024) via the Office/Microsoft 365 update channel as soon as it is available, and verify the patched build under File > Account > About Word. Until patched, avoid opening Word documents from untrusted or unexpected sources and prioritize patching internet-reachable or high-privilege endpoints. Monitor Microsoft's advisory, since no public PoC or in-the-wild exploitation is known yet but the flaw carries high impact if exploited.
| Microsoft 365 Apps | — |
| Microsoft 365 (Office) | — |
| Microsoft Office 2019 | — |
| Microsoft Office 2021 | — |
| Microsoft Office 2024 | — |
| Microsoft Word | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.