CVE-2026-78509
Microsoft Office Outlook heap-based buffer overflow allows unauthenticated remote code execution (CVE-2026-78509)
Microsoft Office Outlook has a critical heap-based buffer overflow (CVE-2026-78509) allowing an unauthenticated attacker to execute code over a network. Apply Microsoft's September 2026 security updates for your Office release.
What happened
Microsoft Office Outlook contains a heap-based buffer overflow (CWE-122). Microsoft describes the result as allowing an unauthorized attacker to execute code over a network. The CVSS 3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C, which means attack complexity is low, no privileges or user interaction are required, and there is high impact on confidentiality, integrity and availability. Microsoft rates the vulnerability critical with a base score of 9.8.
No exploitation or public disclosure is recorded in the data available for this advisory, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalogue. Microsoft has not listed a workaround in its advisory.
Who is affected
Microsoft lists these affected products and version ranges:
- Microsoft 365 Apps for Enterprise 16.0.1 to before 16.0.20326.20138
- Microsoft Office 2019 19.0.0 to before 16.0.10417.20207
- Microsoft Office 365 for Mac 1.0.0 to before 16.113.26091433
- Microsoft Office LTSC 2021 16.0.1 to before 16.0.14334.20906
- Microsoft Office LTSC 2024 16.0.0 to before 16.0.17932.20976
- Microsoft Office LTSC for Mac 2021 16.0.1 to before 16.113.26091433
- Microsoft Office LTSC for Mac 2024 16.0.0 to before 16.113.26091433
- Microsoft Word 2016 16.0.1 to before 16.0.5569.1000
The affected products include these Microsoft Office suites and Word 2016; the vulnerability is described in Microsoft's advisory as an Outlook vulnerability. If your deployment is one of the named products and the installed build is below the corresponding fixed version, it is affected.
What to do now
- Apply Microsoft's security update for your release. The fixed builds are:
- Microsoft 365 Apps for Enterprise 16.0.20326.20138
- Microsoft Office 2019 16.0.10417.20207
- Microsoft Office 365 for Mac 16.113.26091433
- Microsoft Office LTSC 2021 16.0.14334.20906
- Microsoft Office LTSC 2024 16.0.17932.20976
- Microsoft Office LTSC for Mac 2021 16.113.26091433
- Microsoft Office LTSC for Mac 2024 16.113.26091433
- Microsoft Word 2016 16.0.5569.1000 (KB5002923)
- Use Microsoft Update or your normal update-management process, and confirm the affected clients report the fixed build after deployment.
- Microsoft's advisory does not list a workaround. If patching is delayed, reduce network exposure of affected Outlook clients as a pre-patch containment measure.
How to detect it
No vendor-provided indicators of compromise are listed in the advisory. Exposure can be identified by checking installed build numbers for the affected products against the fixed versions above; any build below the relevant fixed version is affected.
Beyond the patch
Beyond applying this update, the severity comes from an unauthenticated network-reachable code execution flaw in a widely deployed office application. Virtual CISO Services (vCISO) help you find and prioritise the network-reachable Office estate before an advisory forces it. Managed Detection & Response (MDR) provides the EDR and SIEM monitoring that would detect code execution or follow-on activity if a similar issue is exploited. For organisations with broad Microsoft licensing, Supply Chain Defense & Third-Party Risk keeps vendor patch and risk obligations visible.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Microsoft 365 Apps for Enterprise | 16.0.1 – < 16.0.20326.20138 | 16.0.20326.20138 |
| Microsoft Office 2019 | 19.0.0 – < 16.0.10417.20207 | 16.0.10417.20207 |
| Microsoft Office 365 for Mac | 1.0.0 – < 16.113.26091433 | 16.113.26091433 |
| Microsoft Office LTSC 2021 | 16.0.1 – < 16.0.14334.20906 | 16.0.14334.20906 |
| Microsoft Office LTSC 2024 | 16.0.0 – < 16.0.17932.20976 | 16.0.17932.20976 |
| Microsoft Office LTSC for Mac 2021 | 16.0.1 – < 16.113.26091433 | 16.113.26091433 |
| Microsoft Office LTSC for Mac 2024 | 16.0.0 – < 16.113.26091433 | 16.113.26091433 |
| Microsoft Word 2016 | 16.0.1 – < 16.0.5569.1000 | 16.0.5569.1000 |