CVE-2026-69742
massInteger Overflow RCE in Microsoft Office Publisher
CVE-2026-69742 is an integer overflow or wraparound flaw (CWE-190) in Microsoft Office Publisher that Microsoft rates High (CVSS 3.1: 8.8) and that allows an unauthenticated attacker to execute code over a network. The CVSS vector includes user interaction (UI:R), which is consistent with the classic Office attack pattern: the attacker sends a specially crafted Publisher document (for example by email) and code runs when the victim opens it. Successful exploitation executes the attacker's code in the context of the logged-in user, with high impact on confidentiality, integrity, and availability — effectively full compromise of the endpoint. Any Microsoft Office installation that includes the Publisher component is potentially affected; the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory for affected and fixed builds. There is currently no evidence of exploitation: no public proof-of-concept is known, the CVE is not in CISA KEV, and EPSS estimates only a 0.8% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for Publisher via the standard Office/Microsoft 365 update channels (Microsoft Update / Office Click-to-Run) and verify the fixed build number against Microsoft's advisory, since specific version ranges are not listed in the source data. Until patched, warn users not to open unsolicited or untrusted .pub files and consider blocking or stripping Publisher attachments at the mail gateway. Continue monitoring Microsoft's advisory and KEV/EPSS feeds for changes in exploitation status.
| Microsoft Office Publisher | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, office 2019, office 2021, office 2024, publisher
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.