Microsoft’s advisory assigns CVE-2026-69678 a Critical severity rating, a CVSS base score of 8.8, and a temporal score of 7.7. Its full vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C. The underlying weakness is CWE-416, a use-after-free condition.
The practical risk is broader than a file a user consciously opens. Microsoft says an attacker could send a specially crafted presentation to a user, and exploitation can occur when that file is opened or rendered in a preview pane, potentially allowing code execution in the user’s context. Microsoft explicitly identifies the Preview Pane as an attack vector.
Publicly disclosed: No. Exploited: No. Microsoft’s exploitation assessment is “Exploitation Less Likely.” Customer action required: Yes.
Preview rendering changes the handling risk
The CVSS vector records no required attacker privileges and low attack complexity, while retaining a user-interaction requirement. In operational terms, the attacker needs to persuade a recipient to receive or encounter a malicious presentation, but does not need an existing account or elevated rights on the victim machine.
The Preview Pane detail should shape triage for organizations that inspect presentation attachments in File Explorer or expose PowerPoint files in collaboration and email workflows. A policy that tells users not to open suspicious slides is not a complete mitigation when Microsoft states that rendering a presentation in preview can trigger the vulnerability. The durable response is to deploy the appropriate fixed build rather than relying on user behavior or preview settings.
Because successful exploitation runs code in the user’s context, the outcome is tied to that account’s access. Systems used by administrators, finance teams, executive staff, developers, and other users with broad access deserve priority deployment even where PowerPoint is not their primary application.
Fixed builds for Microsoft 365 Apps and Office 2019
Microsoft’s published remediation maps Microsoft 365 Apps for Enterprise on both Windows architectures to the same fixed build. Organizations should verify the installed build rather than assume that an Office update has already reached the required level.
- For Microsoft 365 Apps for Enterprise for 32-bit Systems (x86), update to fixed build 16.0.20326.20138 or later.
- For Microsoft 365 Apps for Enterprise for 64-bit Systems (x64), update to fixed build 16.0.20326.20138 or later.
- For Microsoft Office 2019 for 32-bit editions (x86), update to fixed build 16.0.10417.20207 or later.
- For Microsoft Office 2019 for 64-bit editions (x64), update to fixed build 16.0.10417.20207 or later.
The build mapping is significant because the Microsoft 365 Apps for Enterprise remedy is a build-level requirement, not a separately named KB in Microsoft’s affected-product data. Administrators managing update channels should therefore validate that endpoint inventory reports build 16.0.20326.20138 or newer on both x86 and x64 installations.
Office 2019 similarly requires build 16.0.10417.20207 or later for both 32-bit and 64-bit editions. Mixed estates should not treat “Office 2019” as a single deployment target: architecture and servicing model remain relevant to confirming that every PowerPoint installation has reached its assigned fixed version.
LTSC releases have separate Windows build thresholds
Microsoft Office LTSC deployments require different fixed builds depending on whether the installation is Office LTSC 2021 or Office LTSC 2024. The same threshold applies to x86 and x64 within each release generation.
- For Microsoft Office LTSC 2021 for 32-bit editions (x86), update to fixed build 16.0.14334.20906 or later.
- For Microsoft Office LTSC 2021 for 64-bit editions (x64), update to fixed build 16.0.14334.20906 or later.
- For Microsoft Office LTSC 2024 for 32-bit editions (x86), update to fixed build 16.0.17932.20976 or later.
- For Microsoft Office LTSC 2024 for 64-bit editions (x64), update to fixed build 16.0.17932.20976 or later.
This separation is the administrative trap in a broad Office advisory: an organization can be fully current on one servicing branch and still leave another branch below its specific security baseline. Endpoint-management teams should segment reporting by product family and release, then use the fixed build as the compliance test.
The vulnerable component is PowerPoint, but the affected-product list includes complete Office product families because their servicing packages deliver the relevant PowerPoint component. Patch verification should therefore be based on the Office build installed on the device, including endpoints where users rarely launch PowerPoint but still have it installed.
Mac fixes were available September 16
Microsoft states that, as of September 16, 2026, security updates for Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office 365 for Mac are available. Microsoft says customers running those products should ensure the update is installed to be protected from CVE-2026-69678.
- For Microsoft Office 365 for Mac, update to fixed build 16.113.26091433 or later.
- For Microsoft Office LTSC for Mac 2021, update to fixed build 16.113.26091433 or later.
- For Microsoft Office LTSC for Mac 2024, update to fixed build 16.113.26091433 or later.
All three listed Mac products share the same fixed build, 16.113.26091433. That simplifies compliance checking for Mac administrators, but it also means an organization should not assume that an update applied to one licensing variant establishes the patch state of another device. Inventory must identify the installed product and verify the local build.
PowerPoint 2016 requires KB5002920
Microsoft PowerPoint 2016 has a distinct remediation path. Rather than specifying only a servicing-channel build, Microsoft directs customers on both architectures to install KB5002920, which reaches fixed build 16.0.5569.1000.
- For Microsoft PowerPoint 2016 (32-bit edition) (x86), install KB5002920 to reach fixed build 16.0.5569.1000.
- For Microsoft PowerPoint 2016 (64-bit edition) (x64), install KB5002920 to reach fixed build 16.0.5569.1000.
That distinction matters for patch management evidence. A Microsoft 365 Apps or LTSC endpoint can be tested against its specified build threshold; a PowerPoint 2016 endpoint has both an explicit KB deployment requirement and the resulting 16.0.5569.1000 fixed-build target. Reporting should capture the KB5002920 installation and the actual post-installation PowerPoint build where possible.
What to do now
CVE-2026-69678 is an attachment-delivered remote-code-execution risk with a stated Preview Pane path, so the immediate task is to identify every installed PowerPoint servicing branch and bring it to Microsoft’s required build. Prioritize endpoints that routinely receive external presentations or operate under accounts with access to sensitive files, administrative systems, or business-critical services.
For Microsoft 365 Apps for Enterprise, the target is 16.0.20326.20138 or later. Office 2019 requires 16.0.10417.20207 or later; Office LTSC 2021 requires 16.0.14334.20906 or later; Office LTSC 2024 requires 16.0.17932.20976 or later; and the three affected Mac products require 16.113.26091433 or later. PowerPoint 2016 requires KB5002920 and fixed build 16.0.5569.1000.
Microsoft’s advisory makes the decision straightforward: treat previewing a presentation as potentially sufficient exposure, deploy the applicable update, and use the exact build mapping to prove remediation across Windows and Mac fleets.