Microsoft’s advisory assigns the weakness to CWE-121, stack-based buffer overflow. The practical action for administrators is to identify the Office servicing model in use and verify that each installation has reached the applicable fixed build; Microsoft has marked this advisory Customer action required: Yes.
CVE-2026-69686: Severity, scoring, and attack conditions
Microsoft describes CVE-2026-69686 as follows: “Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.” Its severity is Important, with a CVSS base score of 8.8 and a temporal score of 7.7.
The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C. In practical terms, the score reflects a low-complexity remote attack that does not require attacker authentication, but does require user interaction. Microsoft says successful exploitation could allow the attacker to execute code on the affected system, with potential impact to confidentiality, integrity, and availability.
Microsoft’s official advisory specifically says an attacker could convince a user to open a specially crafted document and interact with it in an affected application. That interaction requirement is a meaningful boundary for mail and document-handling workflows: a hostile file must progress beyond delivery and into active use in Word.
The Preview Pane is not an attack vector for this vulnerability, according to Microsoft. That narrows the particular exposure described in the advisory, but it does not change the update requirement for systems where users open Office documents.
The advisory’s current status fields are:
- Publicly disclosed: No.
- Exploited: No.
- Microsoft’s exploitation assessment is Exploitation Less Likely.
- Customer action required: Yes.
Microsoft 365 Apps and Office 2019 fixed builds
Microsoft 365 Apps for Enterprise for 32-bit Systems (x86) must be updated to fixed build 16.0.20326.20138 or later. Microsoft 365 Apps for Enterprise for 64-bit Systems (x64) must also be updated to fixed build 16.0.20326.20138 or later.
Microsoft Office 2019 for 32-bit editions (x86) requires fixed build 16.0.10417.20207 or later. Microsoft Office 2019 for 64-bit editions (x64) likewise requires fixed build 16.0.10417.20207 or later.
The identical Microsoft 365 Apps build target for x86 and x64 systems means architecture alone does not change the target version for enterprise subscription installations. Office 2019 uses a different build branch, so inventory processes that only look for the newer Microsoft 365 Apps version will not establish that Office 2019 is protected.
For Microsoft 365 Apps for Enterprise for 32-bit Systems (x86), update to fixed build 16.0.20326.20138 or later. For Microsoft 365 Apps for Enterprise for 64-bit Systems (x64), update to fixed build 16.0.20326.20138 or later.
For Microsoft Office 2019 for 32-bit editions (x86), update to fixed build 16.0.10417.20207 or later. For Microsoft Office 2019 for 64-bit editions (x64), update to fixed build 16.0.10417.20207 or later.
Office LTSC 2021 and Office LTSC 2024 build targets
Microsoft Office LTSC 2021 for 32-bit editions (x86) requires fixed build 16.0.14334.20906 or later. Microsoft Office LTSC 2021 for 64-bit editions (x64) requires the same fixed build, 16.0.14334.20906 or later.
Microsoft Office LTSC 2024 for 32-bit editions (x86) requires fixed build 16.0.17932.20976 or later. Microsoft Office LTSC 2024 for 64-bit editions (x64) also requires fixed build 16.0.17932.20976 or later.
These are separate servicing targets, despite all four products sharing Word’s underlying vulnerability. Organizations running both LTSC generations need to validate each deployment against its own fixed build rather than treating a single successful update result as evidence that every Office estate is remediated.
For Microsoft Office LTSC 2021 for 32-bit editions (x86), update to fixed build 16.0.14334.20906 or later. For Microsoft Office LTSC 2021 for 64-bit editions (x64), update to fixed build 16.0.14334.20906 or later.
For Microsoft Office LTSC 2024 for 32-bit editions (x86), update to fixed build 16.0.17932.20976 or later. For Microsoft Office LTSC 2024 for 64-bit editions (x64), update to fixed build 16.0.17932.20976 or later.
Mac Office releases and Word 2016
Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 each require fixed build 16.113.26091433 or later. Microsoft states that, as of September 16, 2026, the security update for Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office 365 for Mac is available, and customers running those products should ensure the update is installed to be protected from this vulnerability.
For Microsoft Office 365 for Mac, update to fixed build 16.113.26091433 or later. For Microsoft Office LTSC for Mac 2021, update to fixed build 16.113.26091433 or later. For Microsoft Office LTSC for Mac 2024, update to fixed build 16.113.26091433 or later.
Microsoft Word 2016 has a distinct remediation path. Microsoft Word 2016 (32-bit edition) (x86) requires KB5002923, which reaches fixed build 16.0.5569.1000; Microsoft Word 2016 (64-bit edition) (x64) requires the same KB and fixed build.
For Microsoft Word 2016 (32-bit edition) (x86), install KB5002923 to reach fixed build 16.0.5569.1000. For Microsoft Word 2016 (64-bit edition) (x64), install KB5002923 to reach fixed build 16.0.5569.1000.
What administrators should verify
The MSRC advisory supplies build-based remediation across most affected products rather than a single universal KB. That makes version verification the central operational task, particularly in environments where Microsoft 365 Apps, Office 2019, LTSC editions, Mac installations, and Word 2016 coexist.
Administrators should verify the actual installed product family, processor architecture where relevant, and resulting build number after update deployment. Word 2016 should be checked specifically for KB5002923 and build 16.0.5569.1000, while every other listed Windows and Mac product should be measured against its corresponding fixed build.
The immediate consequence of this advisory is straightforward: machines that run an affected Word release need the specified update level before users handle untrusted documents. Microsoft’s stated attack path depends on opening and interacting with a crafted file, while the fixed-build requirements provide the concrete threshold for closing that exposure.