CVE-2026-69678
Microsoft Office PowerPoint Remote Code Execution Vulnerability
Description
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-69678 is a serious Microsoft PowerPoint security flaw that can let an attacker run code over the network without needing your password; if you use affected Microsoft Office/PowerPoint versions, you should patch right away.
CVE-2026-69678 is an unauthorized remote code execution vulnerability in Microsoft Office PowerPoint caused by a use-after-free condition (CWE-416), where an attacker can craft a malicious file/message to trigger the faulty memory handling and achieve code execution over the network.
What to do now
- Check whether your Microsoft Office/PowerPoint is in one of these affected products/editions: microsoft 365 apps, microsoft office, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft PowerPoint 2016, microsoft 365, office 2019, office 2021, office 2024.
- Confirm the exact installed version of PowerPoint/Office (e.g., in the Office app via About/Account) and compare it to the fixed versions listed below.
- Update to the fixed version for your product line: microsoft 365 apps → 16.0.20326.20138; microsoft office → 16.0.10417.20207 or 16.0.14334.20906 or 16.0.17932.20976; Microsoft PowerPoint 2016 → 16.0.5569.1000.
- If you can’t update immediately, temporarily reduce exposure by avoiding opening Office documents from unexpected sources (especially email attachments/links) until patching is completed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69678 and every CVE in our database. Create a free account — no credit card required.
Create Free Account