Abstract illustration of connected devices separated by a protected security boundary.
Microsoft’s September 21, 2026 security release addresses CVE-2026-77901, an Important Microsoft Office Word remote-code-execution vulnerability affecting supported Microsoft 365 Apps, Office perpetual releases, and Office for Mac; organizations must update to the specified fixed builds or deploy KB5002923 for Word 2016. The flaw requires a user to open a specially crafted attacker-supplied file, but successful exploitation could allow code execution. Microsoft rates exploitation less likely, yet marks customer action as required.

Microsoft’s advisory, published through the Microsoft Security Response Center, identifies a broad Office estate rather than a single Word release. The immediate operational task is straightforward: inventory the applicable Office servicing model and verify that the relevant fixed build has reached every endpoint.

CVE-2026-77901 is a Microsoft Office Word Remote Code Execution Vulnerability​

The exact advisory title is Microsoft Office Word Remote Code Execution Vulnerability. CVE-2026-77901 is an Important-severity issue with a CVSS base score of 8.8 and a CVSS temporal score of 7.7.

Its CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C. Microsoft classifies the weakness as CWE-476, a null pointer dereference.

Microsoft describes the defect as follows: “Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.” The practical delivery condition is important: according to Microsoft, an attacker must get a user to open a specially crafted file to initiate remote code execution.

The advisory explicitly rules out one commonly suspected Office exposure path. The Preview Pane is not an attack vector for CVE-2026-77901. Viewing a file through that pane, by itself, does not meet the documented exploitation condition; opening the crafted file does.

Microsoft’s status fields for this vulnerability are:

  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes

Microsoft’s exploitation assessment is Exploitation Less Likely. That assessment should help teams order their response queue, but it does not change the vendor’s requirement to remediate affected installations.

Microsoft 365 Apps and Office LTSC need build-based remediation​

Most affected Windows Office products use build-based servicing rather than a separately named KB in Microsoft’s supplied mapping. Administrators should verify the installed Office build against the applicable fixed-build threshold, taking care not to substitute a build number from a different product family.

Affected productFixed versionRequired remediation
Microsoft 365 Apps for Enterprise for 32-bit Systems (x86)16.0.20326.20138For Microsoft 365 Apps for Enterprise for 32-bit Systems (x86), update to fixed build 16.0.20326.20138 or later.
Microsoft 365 Apps for Enterprise for 64-bit Systems (x64)16.0.20326.20138For Microsoft 365 Apps for Enterprise for 64-bit Systems (x64), update to fixed build 16.0.20326.20138 or later.
Microsoft Office 2019 for 32-bit editions (x86)16.0.10417.20207For Microsoft Office 2019 for 32-bit editions (x86), update to fixed build 16.0.10417.20207 or later.
Microsoft Office 2019 for 64-bit editions (x64)16.0.10417.20207For Microsoft Office 2019 for 64-bit editions (x64), update to fixed build 16.0.10417.20207 or later.
Microsoft Office LTSC 2021 for 32-bit editions (x86)16.0.14334.20906For Microsoft Office LTSC 2021 for 32-bit editions (x86), update to fixed build 16.0.14334.20906 or later.
Microsoft Office LTSC 2021 for 64-bit editions (x64)16.0.14334.20906For Microsoft Office LTSC 2021 for 64-bit editions (x64), update to fixed build 16.0.14334.20906 or later.
Microsoft Office LTSC 2024 for 32-bit editions (x86)16.0.17932.20976For Microsoft Office LTSC 2024 for 32-bit editions (x86), update to fixed build 16.0.17932.20976 or later.
Microsoft Office LTSC 2024 for 64-bit editions (x64)16.0.17932.20976For Microsoft Office LTSC 2024 for 64-bit editions (x64), update to fixed build 16.0.17932.20976 or later.

The distinction between Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021, and Office LTSC 2024 is operationally significant. Their fixed versions differ, even when the affected application is Word. A machine reaching 16.0.14334.20906, for example, meets the stated threshold for Office LTSC 2021 but is not the fixed-build target given for Microsoft 365 Apps for Enterprise.

Microsoft Office for Mac reaches one fixed build across listed editions​

Microsoft lists three affected Mac products, all remediated by build 16.113.26091433 or later:

Affected productFixed versionRequired remediation
Microsoft Office 365 for Mac16.113.26091433For Microsoft Office 365 for Mac, update to fixed build 16.113.26091433 or later.
Microsoft Office LTSC for Mac 202116.113.26091433For Microsoft Office LTSC for Mac 2021, update to fixed build 16.113.26091433 or later.
Microsoft Office LTSC for Mac 202416.113.26091433For Microsoft Office LTSC for Mac 2024, update to fixed build 16.113.26091433 or later.

Microsoft states that, as of September 16, 2026, the security updates for Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office 365 for Mac are available. Customers running those products should ensure that build 16.113.26091433 or a later build is installed to receive protection for CVE-2026-77901.

This is one area where the update status is clearly defined by the advisory: the Mac security updates were available before the September 21 publication timestamp supplied for the CVE record. Teams responsible for mixed Windows and Mac fleets can therefore treat the Mac remediation as an immediately verifiable build-compliance task rather than a pending release.

Microsoft Word 2016 requires KB5002923 and build 16.0.5569.1000​

Microsoft Word 2016 follows a different remediation path. Both architectures require the same named update and reach the same fixed build:

Affected productKB-to-build mappingRequired remediation
Microsoft Word 2016 (32-bit edition) (x86)KB5002923 → 16.0.5569.1000For Microsoft Word 2016 (32-bit edition) (x86), install KB5002923 to reach fixed build 16.0.5569.1000.
Microsoft Word 2016 (64-bit edition) (x64)KB5002923 → 16.0.5569.1000For Microsoft Word 2016 (64-bit edition) (x64), install KB5002923 to reach fixed build 16.0.5569.1000.

For Word 2016 administrators, the deployment record to look for is therefore KB5002923, followed by confirmation that the installation reports fixed build 16.0.5569.1000. The x86 and x64 variants share the same KB number and fixed-build target, but should still be tracked as the distinct affected products Microsoft names in the advisory.

What this means for you​

Apply the update appropriate to the Office product actually installed, then verify that its build meets Microsoft’s stated fixed version; do not treat the absence of Preview Pane exposure as a reason to defer remediation.

  • Microsoft 365 Apps for Enterprise installations, on both x86 and x64, need build 16.0.20326.20138 or later.
  • Microsoft Office 2019 installations, on both x86 and x64, need build 16.0.10417.20207 or later.
  • Microsoft Office LTSC 2021 installations need build 16.0.14334.20906 or later, while Microsoft Office LTSC 2024 installations need build 16.0.17932.20976 or later.
  • Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024 need build 16.113.26091433 or later.
  • Microsoft Word 2016 on both x86 and x64 requires KB5002923 and fixed build 16.0.5569.1000.
  • The documented attack requires a user to open a specially crafted file, while Microsoft says the Preview Pane is not an attack vector.

CVE-2026-77901 is a file-opening risk in Word with a concrete patch path across subscription, perpetual, and Mac Office releases. Microsoft’s “Exploitation Less Likely” assessment provides useful triage context, but the combination of remote code execution, an 8.8 base score, and a customer-action requirement makes fixed-build verification the sensible completion criterion for Office administrators.