CVE-2026-81385
massUntrusted deserialization RCE in Microsoft Office Publisher
CVE-2026-81385 is a high-severity (CVSS 8.8) deserialization of untrusted data flaw (CWE-502) in Microsoft Office Publisher that allows an unauthorized attacker to execute code over a network. The network attack vector combined with the required user interaction indicates a client-side attack pattern: an attacker would most plausibly deliver a maliciously crafted Publisher document (e.g., via email or download), and code execution is triggered when the victim opens or processes it, with no authentication or privileges needed on the target beforehand. Successful exploitation yields arbitrary code execution on the victim's machine in the context of the user, with high impact on confidentiality, integrity, and availability. Anyone running Microsoft Office Publisher, which is typically installed as part of Microsoft 365/Office desktop suites on Windows endpoints, is affected. There is no known public proof-of-concept and the issue is not in CISA's KEV; EPSS currently puts 30-day exploitation probability at about 1% (62nd percentile), indicating a moderate-to-low likelihood of imminent in-the-wild exploitation.
What to do: Apply Microsoft's security update for Publisher as soon as it is available through Windows Update/the Office update channel and verify your Publisher build against the MSRC advisory for CVE-2026-81385. Until patched, treat unsolicited .pub files from untrusted sources with suspicion and consider filtering .pub attachments at the mail gateway. Note that Publisher is scheduled for retirement by Microsoft in October 2026, so fold migration planning into remediation.
| Microsoft Office Publisher | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, office 2019, office 2021, office 2024, publisher
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.