Junglewise Threat Intelligence

CVE-2026-69632: Microsoft Office use-after-free in remote code execution

CVE-2026-69632 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office is a suite of productivity applications used by millions of organizations for document creation, spreadsheets, and presentations. A use-after-free vulnerability in Office allows an attacker to execute arbitrary code on a user's computer by sending a specially crafted file or document over the network, potentially leading to data theft, system compromise, and lateral movement within an organization.

Technical details

A use-after-free vulnerability exists in Microsoft Office that can be triggered when processing specially crafted files over the network. The vulnerability stems from improper memory management in the affected component, where memory is accessed after it has been freed. An attacker can exploit this by sending a malicious Office document or file to a target user; no authentication is required. Successful exploitation results in arbitrary code execution in the context of the user running Office, allowing an attacker to read, modify, or delete files, install malware, or establish remote access. Patches are expected from Microsoft through their standard security update channels.

Affected products

  • Microsoft Office

Timeline

  • 2026-09-08: disclosed

References

Related threats