CVE-2026-78521
massHeap Buffer Overflow in Microsoft Word Enables Remote Code Execution
CVE-2026-78521 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word, a memory-corruption flaw that occurs when the application processes attacker-controlled content. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates an attacker needs no privileges or credentials and can deliver a crafted file over a network, such as via email, but a user must interact with it, most plausibly by opening or previewing a malicious Word document. Successful exploitation yields arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability. Affected deployments include Word as shipped in Microsoft 365 Apps, Microsoft 365, and the perpetual Office 2019, 2021, and 2024 releases. The flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS assigns a modest 0.6% probability of exploitation within 30 days, so there is currently no confirmed exploitation in the wild.
What to do: Apply Microsoft's security update addressing CVE-2026-78521 across all Office branches in use (Microsoft 365 Apps, Office 2019/2021/2024), and confirm Microsoft 365 Apps are running the latest channel build after update. Until patched, treat Word documents from untrusted senders as suspect and remind users that opening or previewing a crafted file is the required trigger; no public exploit or workaround details are available in the current data.
| Microsoft Word (component of Office/Microsoft 365) | — |
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2019, office 2021, office 2024, word
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.