• PATCH AVAILABLE

CVE-2026-78509: pre-auth remote code execution in Microsoft Microsoft 365 Apps for Enterprise

An unauthenticated attacker can execute arbitrary code on Microsoft 365 Apps for Enterprise components (notably Outlook) over a network. CVE-2026-78509 is a heap-based buffer overflow that can lead to full compromise of affected Office and Microsoft 365 client installs. Affected branches include Microsoft 365 Apps for Enterprise 16.0.1 through before 16.0.20326.20138 and multiple Office and LTSC 16.x releases listed by the vendor; the attacker requires only network access and no user interaction or credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: the flaw allows unauthenticated remote code execution (no credentials required), so prioritize applying vendor fixes or isolating vulnerable clients from untrusted networks immediately.

What is CVE-2026-78509?

An unauthenticated attacker can execute arbitrary code on Microsoft 365 Apps for Enterprise components (notably Outlook) over a network. CVE-2026-78509 is a heap-based buffer overflow that can lead to full compromise of affected Office and Microsoft 365 client installs. Affected branches include Microsoft 365 Apps for Enterprise 16.0.1 through before 16.0.20326.20138 and multiple Office and LTSC 16.x releases listed by the vendor; the attacker requires only network access and no user interaction or credentials. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Microsoft 365 Apps for Enterprise are affected?

BRANCHAFFECTEDFIXED
Microsoft 365 Apps for Enterprise 16.x16.0.1 – before 16.0.20326.2013816.0.20326.20138
Microsoft Office 2019 16.x19.0.0 – before 16.0.10417.2020716.0.10417.20207
Microsoft Office 365 for Mac 16.x1.0.0 – before 16.113.2609143316.113.26091433
Microsoft Office LTSC 2021 16.x16.0.1 – before 16.0.14334.2090616.0.14334.20906
Microsoft Office LTSC 2024 16.x16.0.0 – before 16.0.17932.2097616.0.17932.20976
Microsoft Office LTSC for Mac 2021 16.x16.0.1 – before 16.113.2609143316.113.26091433
Microsoft Office LTSC for Mac 2024 16.x16.0.0 – before 16.113.2609143316.113.26091433
Microsoft Word 2016 16.x16.0.1 – before 16.0.5569.100016.0.5569.1000

Is CVE-2026-78509 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-78509

  1. Apply vendor updates to fixed builds listed by Microsoft (for example 16.0.20326.20138 for Microsoft 365 Apps for Enterprise and the corresponding fixed builds for Office and LTSC branches).
  2. Verify Microsoft Office and Microsoft 365 client versions and patch any installations older than the fixed versions in the vendor advisory.
  3. Restrict network exposure of vulnerable clients and block untrusted access to endpoints running affected Office components until updates are deployed.
  4. Monitor endpoints for unusual behavior and review logs for signs of remote code execution attempts.

Frequently asked questions

Is CVE-2026-78509 being actively exploited?

There are no public reports of exploitation as of 2026-09-30.

Which Microsoft 365 Apps versions are affected by CVE-2026-78509?

Microsoft 365 Apps for Enterprise and several Office/LTSC 16.x branches are affected; examples include 16.0.1 through before 16.0.20326.20138 for Microsoft 365 Apps for Enterprise and the fixed build 16.0.20326.20138.

Is there a patch for CVE-2026-78509?

Yes; Microsoft published fixed builds for each affected branch, including 16.0.20326.20138 for Microsoft 365 Apps for Enterprise and corresponding fixed versions for Office, Mac, and LTSC branches listed by the vendor.

Does CVE-2026-78509 require authentication?

No; the vulnerability permits unauthenticated remote code execution against affected Microsoft Office / Microsoft 365 client components.

References