AI analysis
CVE-2026-78509 is a heap-based buffer overflow (CWE-122) in Microsoft Office Outlook that Microsoft rates Critical (CVSS 3.1: 9.8) and scores as exploitable over a network without authentication or user interaction (AV:N/AC:L/PR:N/UI:N). Per the vector, an attacker who can reach the vulnerable code path can corrupt heap memory and execute arbitrary code without credentials or user action, gaining code execution in the context of the affected Office/Outlook process. Successful exploitation carries high impact to confidentiality, integrity, and availability, effectively full remote code execution on the host, which in enterprise environments typically enables credential theft and lateral movement. Affected products per Microsoft's CPE data are Microsoft 365 / Microsoft 365 Apps, Office 2019, Office 2021, Office 2024, and Word, with the CVE description specifically naming Outlook; the flaw was addressed in the September 2026 Security Update Review. No public proof-of-concept is known, the CVE is not in CISA's KEV, and EPSS estimates only a ~1% probability of exploitation within 30 days (59th percentile), so no in-the-wild exploitation is currently known.
What to do: Deploy the September 2026 security updates for Microsoft 365 Apps, Office 2019/2021/2024, and the Outlook/Word components, and verify installed build numbers against Microsoft's advisory, since no specific fixed versions are given in the source data. Because the flaw is scored as network-exploitable with no user interaction, prioritize Outlook/Office hosts, especially mail-processing endpoints, high-privilege workstations, and RDS/VDI servers. No workarounds are listed in the source data; watch for the addition of a public PoC or a CISA KEV listing as a trigger for accelerated patching.
Affected
| Microsoft Outlook (named in the CVE description; not in the CPE product list) | Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates |
| Microsoft 365 Apps (Office 365 Apps) | Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates |
| Microsoft 365 | Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates |
| Microsoft Office 2019 | Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates |
| Microsoft Office 2021 | Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates |
| Microsoft Office 2024 | Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates |
| Microsoft Word | Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates |
Estimated exposure
mass≈400M+ users/seats (Microsoft 365 commercial-scale installed base, plus standalone Office deployments) — Microsoft 365 is publicly reported at 400M+ paid seats and Office is the dominant desktop office suite, so a parsing flaw in Outlook/Office components plausibly touches an installed base in the hundreds of millions; exact affected builds…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.