CVE-2026-78526
massHeap Buffer Overflow RCE in Microsoft Word (Office 2016–2024, Microsoft 365)
CVE-2026-78526 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that allows an unauthorized attacker to execute arbitrary code over a network. The high CVSS vector requires user interaction (UI:R), which is consistent with the typical trigger: a victim opens or previews a specially crafted Word document, commonly delivered by email or a web link; no privileges or authentication are needed beforehand. On successful exploitation, the attacker gains code execution on the victim's machine, generally in the context of the logged-in user's privileges, potentially leading to full workstation compromise, data theft, and lateral movement. Anyone running Word through Microsoft 365 Apps, Microsoft 365, or the perpetual Office 2016, 2019, 2021, and 2024 editions is affected. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days, though Office RCE bugs are frequently weaponized once details or patch diffs become public.
What to do: Apply Microsoft's current security update for Word/Office (via Windows Update for Office 2016–2024 or the Microsoft 365 Apps update channel) and verify the installed Word build under File > Account > About Word after updating. Because exploitation requires user interaction, reinforce handling of unsolicited email attachments and consider disabling automatic document preview in mail clients until patching is complete. No public exploit is known, but prioritize hosts where users routinely open external documents.
| Microsoft 365 Apps | — |
| Microsoft 365 | — |
| microsoft Office 2016 | — |
| microsoft Office 2019 | — |
| microsoft Office 2021 | — |
| microsoft Office 2024 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, microsoft 365, office 2016, office 2019, office 2021, office 2024
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.