Description
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow in Microsoft Office Access that allows an unauthorized attacker to execute arbitrary code over a network. This flaw, classified as CWE‑121 and CWE‑20, can compromise confidentiality, integrity, and availability on the affected system if exploited.

Affected Systems

Affected products include Microsoft 365 Apps for Enterprise, Microsoft Access 2016 (including the 32‑bit edition), Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. No specific version numbers are listed, but any installation of these packages that has not yet received the latest security update is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and although the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the lack of public exploitation evidence does not diminish the risk. The likely attack vector is via a malicious data packet or file delivered over the network, requiring the victim to use Office Access to open the damaged data; therefore, the vulnerability is exploitable remotely without authentication.

Generated by OpenCVE AI on September 8, 2026 at 23:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office update that addresses CVE‑2026‑69614, which can be downloaded from the Microsoft Security Response Center update guide.
  • Isolate affected machines from untrusted network traffic that could carry corrupted Office Access files or data.
  • Deploy an endpoint protection solution capable of detecting and blocking malicious Office Access files.

Generated by OpenCVE AI on September 8, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Access 2016
Microsoft microsoft Access 2016 (32-bit Edition)
Microsoft microsoft Office 2019
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024
Vendors & Products Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Access 2016
Microsoft microsoft Access 2016 (32-bit Edition)
Microsoft microsoft Office 2019
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024

Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft access
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:access:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:access:2016:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
Vendors & Products Microsoft access

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
Title Microsoft Office Access Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft access 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Weaknesses CWE-121
CWE-20
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:access_2016:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft access 2016
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Access Access 2016 Microsoft 365 Apps For Enterprise Microsoft Access 2016 Microsoft Access 2016 (32-bit Edition) Microsoft Office 2019 Microsoft Office Ltsc 2021 Microsoft Office Ltsc 2024 Office 2019 Office 2021 Office 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-30T15:23:27.826Z

Reserved: 2026-08-03T21:21:00.594Z

Link: CVE-2026-69614

cve-icon Vulnrichment

Updated: 2026-09-09T09:54:26.158Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:33.047

Modified: 2026-09-10T14:34:24.717

Link: CVE-2026-69614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:52:40Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow

  • CWE-20

    Improper Input Validation