ZeroHour

CVE-2026-78520

mass

Out-of-Bounds Read in Microsoft Office Outlook Enables Remote Code Execution

CVSS 3.1
6.5 medium
EPSS
<1%p51
Published
()
Modified
AI analysis

Microsoft has disclosed an out-of-bounds read (CWE-125) in the Outlook component of Microsoft Office that an unauthenticated attacker can trigger over a network, with the vendor description stating that code execution is possible. The CVSS vector (AV:N/AC:L/PR:N/UI:R) shows the attack requires user interaction, most plausibly a user opening or previewing crafted content such as a malicious message or document, and the impact metrics rate confidentiality as high (C:H/I:N/A:N). The affected-product list spans the mainstream Office ecosystem — Microsoft 365 Apps, Microsoft 365, Office 2019, Office 2021, Office 2024, and Word — in addition to the Outlook component named in the description. As of the September 2026 Security Update Review there is no known exploitation, no public proof-of-concept, and no CISA KEV listing, with EPSS assigning only a 0.7% (52nd percentile) probability of exploitation within 30 days.

What to do: Apply Microsoft's September 2026 security updates for Office/Microsoft 365 — covering the Outlook component, Microsoft 365 Apps, Office 2019/2021/2024, and Word — on all endpoints, and verify both perpetual-license and Microsoft 365 Channels installs receive the fix. Because exploitation requires user interaction (UI:R), treat opening or previewing untrusted emails and documents as the primary risk path and reinforce user caution in the interim. With no KEV entry or public PoC, standard patch-cycle prioritization is reasonable, but monitor Microsoft's advisory for the specific fixed build numbers, which are not included in the source data.

Affected
Microsoft 365 Apps
Microsoft 365
microsoft Office 2019
microsoft Office 2021
microsoft Office 2024
microsoft Word
Estimated exposure
masshundreds of millions of users/devices (Microsoft 365/Office install base) — Microsoft 365 and the perpetual Office 2019/2021/2024 lines are deployed across hundreds of millions of commercial seats and well over a billion devices worldwide, and this flaw's affected-product list covers that entire mainstream Office…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, word
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.