Use of uninitialized resource in Microsoft products - CVE-2026-78519
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use of an uninitialized resource in Microsoft Office Outlook when processing a specially crafted email. A remote attacker can send a specially crafted email to a victim to execute arbitrary code.
Exploitation requires the victim to open the email or for Outlook to display its preview.
Affected software
Microsoft Outlook
Microsoft Office
How to mitigate CVE-2026-78519
Microsoft Outlook - update to 16.0.5569.1000
Microsoft Office - addressed in versions 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976