AI analysis
CVE-2026-78519 is a use-of-uninitialized-resource flaw (CWE-908) in Microsoft Office Outlook, disclosed as part of Microsoft's September 2026 Security Update Review, allowing an unauthorized attacker to execute code over a network. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R) indicates the network-based attack requires user interaction, typically opening or previewing attacker-crafted content delivered through Outlook, with no authentication or privileges required. A successful attack would give the attacker code execution with the high confidentiality, integrity, and availability impact reflected in the 8.8 severity score. All users of the listed Outlook components across Microsoft 365 Apps and Office 2019, 2021, and 2024 are affected. There is no evidence of active exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.6% chance of exploitation within 30 days.
What to do: Apply Microsoft's September 2026 security updates to Outlook and all affected Office editions (Microsoft 365 Apps, Office 2019, 2021, and 2024), checking Microsoft's advisory for the fixed build numbers for your update channel, since specific versions are not listed in the source data. Because the CVSS vector requires user interaction, an interim mitigation is to caution users against opening or previewing untrusted email content until patches are deployed. With no public PoC or KEV listing, near-term urgency is moderate, but Outlook's ubiquity warrants prompt, broad patching.
Affected
| microsoft Outlook | — |
| Microsoft 365 Apps | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Estimated exposure
masshundreds of millions of Outlook users (Outlook ships with Microsoft 365/Office, whose installed base is measured in hundreds of millions of seats) — Outlook is bundled with every Microsoft 365/Office desktop suite and is a default corporate email client with a reported installed base in the hundreds of millions of seats, so an Outlook memory-safety flaw plausibly affects the vast…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.