Heap-based buffer overflow in Microsoft products - CVE-2026-78509
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Outlook when processing a specially crafted email message. A remote attacker can send a specially crafted email message to execute arbitrary code.
Viewing the message in the Outlook Reading Pane can trigger the vulnerability without the recipient opening the message or clicking anything in it.
Affected software
Microsoft 365 Apps for Enterprise
Microsoft Office
How to mitigate CVE-2026-78509
Microsoft 365 Apps for Enterprise - update to 16.0.20326.20138
Microsoft Office - addressed in versions 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976