Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has issued fixes for CVE-2026-69671, Microsoft Office Word Remote Code Execution Vulnerability, a heap-based buffer overflow in Word that can let an unauthorized attacker execute code over a network after persuading a user to open and interact with a specially crafted document. The MSRC advisory, published September 17, rates the flaw Important with a CVSS base score of 8.8 and directs organizations to deploy the applicable Office update or fixed build.

The vulnerability affects current Microsoft 365 Apps for Enterprise, perpetual Office 2019 and Office LTSC releases, Office for Mac releases, and Microsoft Word 2016. Microsoft assigns CWE-122, identifying the underlying weakness as a heap-based buffer overflow. Customer action required: Yes.

The attack requires document interaction​

Microsoft’s advisory describes a document-delivery attack rather than a flaw that triggers merely when a file arrives in a mailbox or sits in an Explorer folder. An attacker could convince a user to open a specially crafted document and interact with it in an affected application; successful exploitation could allow the attacker to execute code on the affected system.

The advisory specifically answers a common Office-security triage question: the Preview Pane is not an attack vector for CVE-2026-69671. That narrows the immediate trigger condition, but it does not remove the operational risk for organizations where Word documents are routinely exchanged through email, cloud-sharing links, ticketing systems, or collaboration workflows. The risk point is the user opening and interacting with the crafted file in an affected application.

Microsoft’s CVSS v3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C. The vector records network attackability, low attack complexity, no privileges required, required user interaction, unchanged scope, and high potential effects on confidentiality, integrity, and availability. The temporal score is 7.7.

Publicly disclosed: No. Exploited: No. Microsoft’s exploitation assessment is “Exploitation Less Likely.”

A wide set of Word installations needs attention​

The affected-product list covers both 32-bit and 64-bit Windows deployments where applicable, plus Microsoft’s current and LTSC Mac Office branches. For administrators, the important practical point is that the required build differs substantially by servicing product: a Microsoft 365 Apps deployment must not be evaluated against the Office 2019 or LTSC build numbers, and vice versa.

Microsoft lists the following Windows products and fixed-build mappings:

  • Microsoft 365 Apps for Enterprise for 32-bit Systems (x86) must be updated to fixed build 16.0.20326.20138 or later.
  • Microsoft 365 Apps for Enterprise for 64-bit Systems (x64) must be updated to fixed build 16.0.20326.20138 or later.
  • Microsoft Office 2019 for 32-bit editions (x86) must be updated to fixed build 16.0.10417.20207 or later.
  • Microsoft Office 2019 for 64-bit editions (x64) must be updated to fixed build 16.0.10417.20207 or later.
  • Microsoft Office LTSC 2021 for 32-bit editions (x86) must be updated to fixed build 16.0.14334.20906 or later.
  • Microsoft Office LTSC 2021 for 64-bit editions (x64) must be updated to fixed build 16.0.14334.20906 or later.
  • Microsoft Office LTSC 2024 for 32-bit editions (x86) must be updated to fixed build 16.0.17932.20976 or later.
  • Microsoft Office LTSC 2024 for 64-bit editions (x64) must be updated to fixed build 16.0.17932.20976 or later.
  • Microsoft Word 2016 (32-bit edition) (x86) requires KB5002923 to reach fixed build 16.0.5569.1002.
  • Microsoft Word 2016 (64-bit edition) (x64) requires KB5002923 to reach fixed build 16.0.5569.1002.

The KB-to-build mapping is unusually direct for Word 2016: KB5002923 is the named remediation package for both architectures, with 16.0.5569.1002 as the required fixed build. The newer Office product families are instead specified by their target builds. Admins should use the product’s own servicing mechanism to reach the listed build or a later one, rather than treating KB5002923 as a universal Office update.

Mac fixes were available before publication​

Microsoft also lists Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 as affected products. Each requires fixed build 16.113.26091433 or later.

Microsoft states that, as of September 16, 2026, the security update for Microsoft Office LTSC for Mac 2021, 2024 and Microsoft Office 365 for Mac is available. Customers running those products should ensure the update is installed to be protected from CVE-2026-69671.

The Mac remediation mapping is:

  • For Microsoft Office 365 for Mac, update to fixed build 16.113.26091433 or later.
  • For Microsoft Office LTSC for Mac 2021, update to fixed build 16.113.26091433 or later.
  • For Microsoft Office LTSC for Mac 2024, update to fixed build 16.113.26091433 or later.

This is a useful distinction for mixed-platform Office estates. The Windows fixed builds use the 16.0 version format and vary by product generation, while the listed Mac products share fixed build 16.113.26091433. Inventory and compliance rules need to account for that platform-specific versioning rather than applying a single numerical threshold to every Office installation.

Deploy by product channel and verify the resulting build​

Microsoft’s remediation guidance is explicit for every affected product:

  • For Microsoft 365 Apps for Enterprise for 32-bit Systems (x86), update to fixed build 16.0.20326.20138 or later.
  • For Microsoft 365 Apps for Enterprise for 64-bit Systems (x64), update to fixed build 16.0.20326.20138 or later.
  • For Microsoft Office 2019 for 32-bit editions (x86), update to fixed build 16.0.10417.20207 or later.
  • For Microsoft Office 2019 for 64-bit editions (x64), update to fixed build 16.0.10417.20207 or later.
  • For Microsoft Office 365 for Mac, update to fixed build 16.113.26091433 or later.
  • For Microsoft Office LTSC 2021 for 32-bit editions (x86), update to fixed build 16.0.14334.20906 or later.
  • For Microsoft Office LTSC 2021 for 64-bit editions (x64), update to fixed build 16.0.14334.20906 or later.
  • For Microsoft Office LTSC 2024 for 32-bit editions (x86), update to fixed build 16.0.17932.20976 or later.
  • For Microsoft Office LTSC 2024 for 64-bit editions (x64), update to fixed build 16.0.17932.20976 or later.
  • For Microsoft Office LTSC for Mac 2021, update to fixed build 16.113.26091433 or later.
  • For Microsoft Office LTSC for Mac 2024, update to fixed build 16.113.26091433 or later.
  • For Microsoft Word 2016 (32-bit edition) (x86), install KB5002923 to reach fixed build 16.0.5569.1002.
  • For Microsoft Word 2016 (64-bit edition) (x64), install KB5002923 to reach fixed build 16.0.5569.1002.

The administrative task is therefore more than approving one update: identify the Office product and architecture installed on each endpoint, deliver its matching update, and verify the resulting version against Microsoft’s fixed-build threshold. Teams that assess only whether an update job reported success can miss the central question in this advisory—whether the device actually reached the build that contains the fix.

For users, the interim operational message follows directly from Microsoft’s attack description: treat unsolicited or unexpected Word documents as potentially hostile, particularly when the sender or document context cannot be independently validated. But the durable remediation is to bring every affected Office installation to its product-specific fixed version, with KB5002923 required for Word 2016.