ZeroHour

CVE-2026-81385

mass

Untrusted deserialization RCE in Microsoft Office Publisher

CVSS 3.1
8.8 high
EPSS
1%p61
Published
()
Modified
AI analysis

CVE-2026-81385 is a high-severity (CVSS 8.8) deserialization of untrusted data flaw (CWE-502) in Microsoft Office Publisher that allows an unauthorized attacker to execute code over a network. The network attack vector combined with the required user interaction indicates a client-side attack pattern: an attacker would most plausibly deliver a maliciously crafted Publisher document (e.g., via email or download), and code execution is triggered when the victim opens or processes it, with no authentication or privileges needed on the target beforehand. Successful exploitation yields arbitrary code execution on the victim's machine in the context of the user, with high impact on confidentiality, integrity, and availability. Anyone running Microsoft Office Publisher, which is typically installed as part of Microsoft 365/Office desktop suites on Windows endpoints, is affected. There is no known public proof-of-concept and the issue is not in CISA's KEV; EPSS currently puts 30-day exploitation probability at about 1% (62nd percentile), indicating a moderate-to-low likelihood of imminent in-the-wild exploitation.

What to do: Apply Microsoft's security update for Publisher as soon as it is available through Windows Update/the Office update channel and verify your Publisher build against the MSRC advisory for CVE-2026-81385. Until patched, treat unsolicited .pub files from untrusted sources with suspicion and consider filtering .pub attachments at the mail gateway. Note that Publisher is scheduled for retirement by Microsoft in October 2026, so fold migration planning into remediation.

Affected
Microsoft Office Publisher
Estimated exposure
masslikely millions to tens of millions of users (Publisher ships with many Office/Microsoft 365 desktop suites) — Microsoft's Office and Microsoft 365 desktop suites that bundle Publisher are deployed across hundreds of millions of enterprise and consumer seats, so even a partial share of bundled installs places affected users in the millions, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, office 2019, office 2021, office 2024, publisher
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.