CVE-2026-80081: Microsoft Office PowerPoint Remote Code Execution Vulnerability

Overview

Severity
N/A
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Sep
Released
2026-09-08

Description

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

FAQ

Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector. How could an attacker exploit this vulnerability? An attacker could send a specially crafted PowerPoint presentation containing malicious linked media to a target user. The user would need to open the presentation, start the slideshow, and allow the linked content. Successful exploitation could allow the attacker to execute code on the user's system. Authentication is not required.

Affected Products (2)

Microsoft Office

  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft 365 Apps for Enterprise for 64-bit Systems

Acknowledgments

<a href="https://www.linkedin.com/in/boolgombear/">Minjea Park</a>, Jmini

Revision History

  • 2026-09-08: Information published.