Junglewise Threat Intelligence

CVE-2026-80086: Microsoft Office PowerPoint out-of-bounds read

CVE-2026-80086 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft PowerPoint contains a vulnerability that allows an attacker to read memory beyond intended boundaries through a specially crafted file. An attacker can exploit this flaw remotely to extract sensitive information, such as credentials or document content, without requiring user interaction or prior authentication. This could lead to unauthorized disclosure of confidential business data.

Technical details

An out-of-bounds read vulnerability exists in Microsoft PowerPoint's file parsing logic, allowing an attacker to access memory outside allocated buffers. The vulnerability is triggered when processing a maliciously crafted PowerPoint file, which can be delivered remotely over a network. No authentication or user interaction is required beyond opening the malicious file. An attacker can exploit this to read sensitive data from the application's memory, potentially exposing credentials, encryption keys, or document contents. Microsoft has issued a security update addressing this issue.

Affected products

  • Microsoft Office PowerPoint

Timeline

  • 2026-09-08: disclosed

References

Related threats