ZeroHour

CVE-2026-78509

mass

Heap-Based Buffer Overflow RCE in Microsoft Office and Outlook

CVSS 3.1
9.8 critical
EPSS
<1%p59
Published
()
Modified
AI analysis

CVE-2026-78509 is a heap-based buffer overflow (CWE-122) in Microsoft Office Outlook that Microsoft rates Critical (CVSS 3.1: 9.8) and scores as exploitable over a network without authentication or user interaction (AV:N/AC:L/PR:N/UI:N). Per the vector, an attacker who can reach the vulnerable code path can corrupt heap memory and execute arbitrary code without credentials or user action, gaining code execution in the context of the affected Office/Outlook process. Successful exploitation carries high impact to confidentiality, integrity, and availability, effectively full remote code execution on the host, which in enterprise environments typically enables credential theft and lateral movement. Affected products per Microsoft's CPE data are Microsoft 365 / Microsoft 365 Apps, Office 2019, Office 2021, Office 2024, and Word, with the CVE description specifically naming Outlook; the flaw was addressed in the September 2026 Security Update Review. No public proof-of-concept is known, the CVE is not in CISA's KEV, and EPSS estimates only a ~1% probability of exploitation within 30 days (59th percentile), so no in-the-wild exploitation is currently known.

What to do: Deploy the September 2026 security updates for Microsoft 365 Apps, Office 2019/2021/2024, and the Outlook/Word components, and verify installed build numbers against Microsoft's advisory, since no specific fixed versions are given in the source data. Because the flaw is scored as network-exploitable with no user interaction, prioritize Outlook/Office hosts, especially mail-processing endpoints, high-privilege workstations, and RDS/VDI servers. No workarounds are listed in the source data; watch for the addition of a public PoC or a CISA KEV listing as a trigger for accelerated patching.

Affected
Microsoft Outlook (named in the CVE description; not in the CPE product list)Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates
Microsoft 365 Apps (Office 365 Apps)Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates
Microsoft 365Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates
Microsoft Office 2019Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates
Microsoft Office 2021Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates
Microsoft Office 2024Affected version ranges not enumerated in the source data; fixed via the September 2026 security updates
Microsoft WordAffected version ranges not enumerated in the source data; fixed via the September 2026 security updates
Estimated exposure
mass≈400M+ users/seats (Microsoft 365 commercial-scale installed base, plus standalone Office deployments) — Microsoft 365 is publicly reported at 400M+ paid seats and Office is the dominant desktop office suite, so a parsing flaw in Outlook/Office components plausibly touches an installed base in the hundreds of millions; exact affected builds…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.