ZeroHour

CVE-2026-78519

mass

Use of Uninitialized Resource in Microsoft Outlook Allows Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p47
Published
()
Modified
AI analysis

CVE-2026-78519 is a use-of-uninitialized-resource flaw (CWE-908) in Microsoft Office Outlook, disclosed as part of Microsoft's September 2026 Security Update Review, allowing an unauthorized attacker to execute code over a network. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R) indicates the network-based attack requires user interaction, typically opening or previewing attacker-crafted content delivered through Outlook, with no authentication or privileges required. A successful attack would give the attacker code execution with the high confidentiality, integrity, and availability impact reflected in the 8.8 severity score. All users of the listed Outlook components across Microsoft 365 Apps and Office 2019, 2021, and 2024 are affected. There is no evidence of active exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.6% chance of exploitation within 30 days.

What to do: Apply Microsoft's September 2026 security updates to Outlook and all affected Office editions (Microsoft 365 Apps, Office 2019, 2021, and 2024), checking Microsoft's advisory for the fixed build numbers for your update channel, since specific versions are not listed in the source data. Because the CVSS vector requires user interaction, an interim mitigation is to caution users against opening or previewing untrusted email content until patches are deployed. With no public PoC or KEV listing, near-term urgency is moderate, but Outlook's ubiquity warrants prompt, broad patching.

Affected
microsoft Outlook
Microsoft 365 Apps
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
Estimated exposure
masshundreds of millions of Outlook users (Outlook ships with Microsoft 365/Office, whose installed base is measured in hundreds of millions of seats) — Outlook is bundled with every Microsoft 365/Office desktop suite and is a default corporate email client with a reported installed base in the hundreds of millions of seats, so an Outlook memory-safety flaw plausibly affects the vast…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, office 2019, office 2021, office 2024, outlook
Weakness
CWE-908
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.