CVE-2026-69360: Microsoft Office Word Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Office Word Remote Code Execution Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Office Word
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to do to exploit this issue?
The attacker does not need prior privileges and can exploit the issue over a network, but user interaction is required. The supplied data does not specify the exact interaction or delivery method.
2
What level of impact could successful exploitation have?
Successful exploitation could allow code execution and has high confidentiality, integrity, and availability impact. This could enable an attacker to access, alter, or disrupt affected systems.