CVE-2026-68809: Powerpoint Information Disclosure Vulnerability
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Other sources
Powerpoint Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002899 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68809?
The severity of CVE-2026-68809 is medium with a score of 5.5.
What does CVE-2026-68809 entail?
CVE-2026-68809 involves an incomplete cleanup vulnerability in Microsoft PowerPoint that may allow an unauthorized attacker to disclose information locally.
How can I mitigate the risks associated with CVE-2026-68809?
To mitigate the risks associated with CVE-2026-68809, ensure that you are using the latest version of Microsoft PowerPoint and apply any security patches provided by Microsoft.
Which software versions are affected by CVE-2026-68809?
CVE-2026-68809 affects various versions of Microsoft PowerPoint, including Microsoft PowerPoint 2016 and 2019, as well as Microsoft 365 Apps for Enterprise and LTSC editions.
Is CVE-2026-68809 an information disclosure vulnerability?
Yes, CVE-2026-68809 is classified as an information disclosure vulnerability due to its potential to allow unauthorized access to sensitive information.