Executive brief
Microsoft Office contains a buffer over-read vulnerability that allows an attacker to disclose sensitive information over a network without requiring authorization. This could expose confidential data contained in memory, potentially compromising user privacy and sensitive business information processed through Office applications.
Technical details
A buffer over-read vulnerability exists in Microsoft Office where a specially crafted input can cause the application to read beyond allocated memory boundaries. The vulnerability is triggered over the network and allows information disclosure; an attacker can craft a malicious document or network request to trigger the out-of-bounds read and leak data from adjacent memory regions. No authentication is required to exploit this issue. The vulnerability has been assigned CVE-2026-69626 with a CVSS score of 6.5.
Affected products
- Microsoft Office
Timeline
- 2026-09-08: disclosed