CVE-2026-69778
massHeap Buffer Overflow in Microsoft Office Access Enables Remote Code Execution
CVE-2026-69778 is a heap-based buffer overflow (CWE-122) in Microsoft Access, the database application bundled with Microsoft Office and Microsoft 365. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates the flaw is reachable over a network without special privileges but requires user interaction, most likely by convincing a user to open a maliciously crafted Access database file. Successful exploitation allows an unauthorized attacker to execute arbitrary code in the context of the user, with high impact on confidentiality, integrity, and availability (CVSS 8.8). Any user running Microsoft Access via supported Office or Microsoft 365 installations is affected. There is currently no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.8% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's security update for Access as soon as it is published through Microsoft's standard update channels (Microsoft Update, WSUS, or your endpoint management platform); specific patched build numbers are not listed in the available data. Until systems are patched, avoid opening .accdb/.mdb files from untrusted sources and remind users, since exploitation requires user interaction. Inventory your estate for Access deployments (e.g., Office Professional installs and Microsoft 365 E3/E5 seats) to prioritize patching.
| Microsoft Office Access (Microsoft Access, the database component of Microsoft Office / Microsoft 365) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, access, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.