Heap-based buffer overflow in Microsoft products - CVE-2026-78521
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office Word when processing malicious mail-merge data. A remote attacker can send a specially crafted Word document containing malicious mail-merge data to execute arbitrary code.
User interaction is required to open the document and process or update its mail-merge data. The Preview Pane is not an attack vector.
Affected software
Microsoft 365 Apps for Enterprise
Microsoft Office
How to mitigate CVE-2026-78521
Microsoft 365 Apps for Enterprise - update to 16.0.20326.20138
Microsoft Office - addressed in versions 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976