Junglewise Threat Intelligence

CVE-2026-69529: Microsoft Office Access heap-based buffer overflow

CVE-2026-69529 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Office Access. Vendors: Microsoft.

Executive brief

Microsoft Office Access is a desktop database application used by organizations to create and manage databases. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code on affected systems over the network without requiring authorization, potentially compromising data integrity and enabling system takeover.

Technical details

A heap-based buffer overflow exists in Microsoft Office Access that permits remote code execution. The vulnerability is reachable over the network and does not require prior authentication or user interaction to trigger. An attacker can exploit this flaw to execute arbitrary code with the privileges of the user running Office Access, potentially leading to full system compromise. Microsoft has released security patches to remediate this issue.

Affected products

  • Microsoft Office Access

Timeline

  • 2026-09-08: disclosed

References

Related threats