Use-After-Free RCE in Microsoft PowerPoint (Office 2019/2021/2024 & Microsoft 365)
AI analysis
CVE-2026-69767 is a use-after-free (CWE-416) memory-safety flaw in Microsoft Office PowerPoint that an unauthenticated remote attacker can exploit to execute code. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates the attacker needs no credentials but must rely on user interaction, consistent with the victim opening or previewing a specially crafted PowerPoint file such as an email attachment or downloaded deck; the freed-then-reused memory is then corrupted in a way the attacker can leverage. Successful exploitation yields remote code execution with high impact on confidentiality, integrity and availability, running with the privileges of the user who opened the file. Affected deployments include Microsoft 365 Apps and Microsoft 365, plus the perpetual Office 2019, Office 2021 and Office 2024 editions that include PowerPoint. As of the September 2026 Patch Tuesday advisory there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns roughly a 0.8% probability of exploitation within 30 days (55th percentile).
What to do: Apply Microsoft's September 2026 Patch Tuesday Office/PowerPoint security updates to Microsoft 365 Apps and Office 2019/2021/2024 deployments, prioritizing workstations that open untrusted files, and verify installed Office build numbers against Microsoft's advisory. Until patched, discourage opening PowerPoint files from untrusted sources and rely on Protected View, email attachment sandboxing and Attack Surface Reduction rules as interim mitigations. No exploit or in-the-wild activity is known, so standard patch-cycle cadence is reasonable, but treat the 8.8 severity as a priority within the month.
Affected
| Microsoft 365 Apps (PowerPoint component) | — |
| Microsoft 365 (PowerPoint component) | — |
| Microsoft Office 2019 (PowerPoint component) | — |
| Microsoft Office 2021 (PowerPoint component) | — |
| Microsoft Office 2024 (PowerPoint component) | — |
| Microsoft PowerPoint | Standalone/PowerPoint CPE listed by the CVE; affected build ranges per Microsoft's September 2026 advisory |
Estimated exposure
masshundreds of millions of users/devices (Office and PowerPoint are bundled across enterprise and consumer installs of Microsoft 365 and perpetual Office… — Microsoft 365 alone is deployed on hundreds of millions of paid seats and PowerPoint ships with every affected edition, so the potentially exposed install base plausibly exceeds one million users by orders of magnitude; this is an…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.