Skip to content

CVE-2026-78509

Microsoft Office Outlook heap-based buffer overflow allows unauthenticated remote code execution (CVE-2026-78509)

Critical 9.8 Vendor: Microsoft Published

Microsoft Office Outlook has a critical heap-based buffer overflow (CVE-2026-78509) allowing an unauthenticated attacker to execute code over a network. Apply Microsoft's September 2026 security updates for your Office release.

What happened

Microsoft Office Outlook contains a heap-based buffer overflow (CWE-122). Microsoft describes the result as allowing an unauthorized attacker to execute code over a network. The CVSS 3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C, which means attack complexity is low, no privileges or user interaction are required, and there is high impact on confidentiality, integrity and availability. Microsoft rates the vulnerability critical with a base score of 9.8.

No exploitation or public disclosure is recorded in the data available for this advisory, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalogue. Microsoft has not listed a workaround in its advisory.

Who is affected

Microsoft lists these affected products and version ranges:

  • Microsoft 365 Apps for Enterprise 16.0.1 to before 16.0.20326.20138
  • Microsoft Office 2019 19.0.0 to before 16.0.10417.20207
  • Microsoft Office 365 for Mac 1.0.0 to before 16.113.26091433
  • Microsoft Office LTSC 2021 16.0.1 to before 16.0.14334.20906
  • Microsoft Office LTSC 2024 16.0.0 to before 16.0.17932.20976
  • Microsoft Office LTSC for Mac 2021 16.0.1 to before 16.113.26091433
  • Microsoft Office LTSC for Mac 2024 16.0.0 to before 16.113.26091433
  • Microsoft Word 2016 16.0.1 to before 16.0.5569.1000

The affected products include these Microsoft Office suites and Word 2016; the vulnerability is described in Microsoft's advisory as an Outlook vulnerability. If your deployment is one of the named products and the installed build is below the corresponding fixed version, it is affected.

What to do now

  1. Apply Microsoft's security update for your release. The fixed builds are:
  • Microsoft 365 Apps for Enterprise 16.0.20326.20138
  • Microsoft Office 2019 16.0.10417.20207
  • Microsoft Office 365 for Mac 16.113.26091433
  • Microsoft Office LTSC 2021 16.0.14334.20906
  • Microsoft Office LTSC 2024 16.0.17932.20976
  • Microsoft Office LTSC for Mac 2021 16.113.26091433
  • Microsoft Office LTSC for Mac 2024 16.113.26091433
  • Microsoft Word 2016 16.0.5569.1000 (KB5002923)
  1. Use Microsoft Update or your normal update-management process, and confirm the affected clients report the fixed build after deployment.
  2. Microsoft's advisory does not list a workaround. If patching is delayed, reduce network exposure of affected Outlook clients as a pre-patch containment measure.

How to detect it

No vendor-provided indicators of compromise are listed in the advisory. Exposure can be identified by checking installed build numbers for the affected products against the fixed versions above; any build below the relevant fixed version is affected.

Beyond the patch

Beyond applying this update, the severity comes from an unauthenticated network-reachable code execution flaw in a widely deployed office application. Virtual CISO Services (vCISO) help you find and prioritise the network-reachable Office estate before an advisory forces it. Managed Detection & Response (MDR) provides the EDR and SIEM monitoring that would detect code execution or follow-on activity if a similar issue is exploited. For organisations with broad Microsoft licensing, Supply Chain Defense & Third-Party Risk keeps vendor patch and risk obligations visible.

Affected and fixed versions

ProductAffectedFixed in
Microsoft 365 Apps for Enterprise16.0.1 – < 16.0.20326.2013816.0.20326.20138
Microsoft Office 201919.0.0 – < 16.0.10417.2020716.0.10417.20207
Microsoft Office 365 for Mac1.0.0 – < 16.113.2609143316.113.26091433
Microsoft Office LTSC 202116.0.1 – < 16.0.14334.2090616.0.14334.20906
Microsoft Office LTSC 202416.0.0 – < 16.0.17932.2097616.0.17932.20976
Microsoft Office LTSC for Mac 202116.0.1 – < 16.113.2609143316.113.26091433
Microsoft Office LTSC for Mac 202416.0.0 – < 16.113.2609143316.113.26091433
Microsoft Word 201616.0.1 – < 16.0.5569.100016.0.5569.1000

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.