CVE-2026-80081: Microsoft Office PowerPoint Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Microsoft Office PowerPoint Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
— Microsoft
Affected Software
3 affected componentsFixes available
Microsoft Office PowerPoint
Microsoft 365 Apps for Enterprise<16.0.20326.20136
16.0.20326.20136
Microsoft 365 Apps for Enterprise<16.0.20326.20136
16.0.20326.20136
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20136
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
DescriptionSeverity
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
DescriptionSeverity
Frequently Asked Questions
1
Does exploitation require an authenticated account or user interaction?
The attacker does not need privileges, but exploitation requires user interaction. The attack vector is network-based and has low attack complexity.
2
Which software is identified as affected?
The affected software listed is Microsoft 365 Apps for Enterprise and Microsoft Office PowerPoint.