Description
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow in Microsoft Office Access that allows an unauthorized attacker to execute arbitrary code over a network. This flaw, classified as CWE‑121 and CWE‑20, can compromise confidentiality, integrity, and availability on the affected system if exploited.

Affected Systems

Affected products include Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (including the 32‑bit edition), Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. No specific version numbers are listed, but any installation of these packages that has not yet received the latest security update is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and although the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the lack of public exploitation evidence does not diminish the risk. The likely attack vector is via a malicious data packet or file delivered over the network, requiring the victim to use Office Access to open the damaged data; therefore, the vulnerability is exploitable remotely without authentication.

Generated by OpenCVE AI on September 8, 2026 at 23:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office update that addresses CVE‑2026‑69614, which can be downloaded from the Microsoft Security Response Center update guide.
  • Isolate affected machines from untrusted network traffic that could carry corrupted Office Access files or data.
  • Deploy an endpoint protection solution capable of detecting and blocking malicious Office Access files.

Generated by OpenCVE AI on September 8, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
Title Microsoft Office Access Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft access 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Weaknesses CWE-121
CWE-20
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:access_2016:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft access 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Access 2016 Office 2019 Office 2021 Office 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:40:36.986Z

Reserved: 2026-08-03T21:21:00.594Z

Link: CVE-2026-69614

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:33.047

Modified: 2026-09-08T18:39:34.660

Link: CVE-2026-69614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T23:45:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow

  • CWE-20

    Improper Input Validation