AI analysis
CVE-2026-78439 is a stack-based buffer overflow (CWE-121) in the Microsoft Graphics Component, rated High severity (CVSS 3.1: 8.8). It is reachable over a network without authentication, but the CVSS vector includes UI:R (user interaction required), meaning an attacker most plausibly triggers it by convincing a user to open or preview attacker-supplied content such as a crafted file. Successful exploitation gives the attacker code execution in the context of the local user, with high impact on confidentiality, integrity, and availability. Any Windows system running an affected version of the Graphics Component is potentially exposed; the source data does not enumerate specific Windows versions or builds, so defenders should check Microsoft's September 2026 security release for the exact affected ranges. There is currently no known in-the-wild exploitation, no public proof of concept, and the flaw is not listed in CISA's KEV, with EPSS assigning a 0.6% probability of exploitation within 30 days (48th percentile).
What to do: Apply the Windows/Graphics Component fixes included in Microsoft's September 2026 security updates across all endpoints, prioritizing user workstations where file previewing is common. Until systems are patched, encourage users not to open or preview untrusted files and email attachments. Because exploitation requires user interaction and there is no public PoC or KEV listing, normal monthly patching cadence is likely adequate, but monitor Microsoft's advisory for revised affected-version details.
Affected
| Microsoft Graphics Component (ships with Windows) | — |
Estimated exposure
mass≈1 billion Windows devices (Graphics Component is a core component present on effectively all Windows installs) — The Graphics Component ships with every Windows installation and Windows' global install base is estimated at over a billion devices, though actual exploitation additionally requires user interaction with malicious content.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.