CVE-2026-69797 – Microsoft Office PowerPoint Remote Code Execution Vulnerability

CVSS 8.8 IMPORTANT Critical - Same Day Deployment

“A malicious PowerPoint file could turn a routine document opening or preview into remote code execution, putting sensitive data and systems at risk.”

CVE-2026-69797 is a critical remote code execution vulnerability in Microsoft Office PowerPoint caused by a use-after-free weakness (CWE-416). An unauthorized attacker can send a specially crafted presentation that may trigger the vulnerability when a user opens the file or it is rendered in a preview pane. Successful exploitation could execute code in the user’s context and result in significant confidentiality, integrity, and availability impact.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.