Junglewise Threat Intelligence

CVE-2026-69742: Microsoft Office Publisher integer overflow

CVE-2026-69742 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Publisher is a document design and publishing application used by many organizations for creating marketing materials and business documents. An integer overflow vulnerability allows an attacker to execute arbitrary code when a user opens a malicious Publisher file, potentially compromising the system and accessing sensitive business information.

Technical details

An integer overflow or wraparound vulnerability exists in Microsoft Office Publisher's file parsing logic. The vulnerability is triggered when processing specially crafted Publisher documents and can lead to remote code execution. Attack delivery is likely via email or web-based file sharing, with user interaction required (opening the malicious document). An attacker can achieve code execution in the context of the user opening the file, bypassing normal application security boundaries.

Affected products

  • Microsoft Office Publisher

Timeline

  • 2026-09-08: disclosed

References

Related threats