AI analysis
CVE-2026-69797 is a use-after-free memory corruption flaw in Microsoft Office PowerPoint that Microsoft rates High (8.8) and classifies as remote code execution. An unauthenticated remote attacker can trigger it by convincing a user to open (or per the user-interaction requirement in the CVSS vector, possibly just preview) a specially crafted PowerPoint presentation, causing the application to access memory that has already been freed. Successful exploitation executes arbitrary code in the context of the current user, giving the attacker the victim's privileges with high impact on confidentiality, integrity, and availability within that user scope, and a foothold for further compromise of the host and network. Anyone running PowerPoint within Microsoft 365 Apps, Microsoft 365, or the perpetual Office 2019, 2021, and 2024 suites is in scope. There is currently no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 0.8%, so no exploitation is known at disclosure; fixes are expected in Microsoft's September 2026 Patch Tuesday updates.
What to do: Apply Microsoft's September 2026 security updates for Office/PowerPoint (covering Microsoft 365 Apps and Office 2019/2021/2024) as a priority and verify post-patch that PowerPoint builds are current. Until patched, treat unsolicited PowerPoint files as untrusted, avoid opening or previewing them (including via mail preview panes), and consider flagging or sandboxing .ppt/.pptx attachments at email gateways. No workarounds or in-the-wild exploitation are confirmed, so patching is the primary mitigation.
Affected
| Microsoft 365 Apps (PowerPoint component) | — |
| Microsoft 365 (PowerPoint component) | — |
| Microsoft Office 2019 (PowerPoint component) | — |
| Microsoft Office 2021 (PowerPoint component) | — |
| Microsoft Office 2024 (PowerPoint component) | — |
| Microsoft PowerPoint (desktop application) | — |
Estimated exposure
masshundreds of millions of endpoints/users (Microsoft 365 has roughly 400M+ paid seats and Office/PowerPoint is historically installed on well over a billion… — PowerPoint ships in every Microsoft 365 and perpetual Office deployment on corporate and consumer Windows desktops, so exposure is effectively global at an order of hundreds of millions of installations.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.