DIRAS TAKE
Treat this as urgent: the flaw allows unauthenticated remote code execution (no credentials required), so prioritize applying vendor fixes or isolating vulnerable clients from untrusted networks immediately.
What is CVE-2026-78509?
An unauthenticated attacker can execute arbitrary code on Microsoft 365 Apps for Enterprise components (notably Outlook) over a network. CVE-2026-78509 is a heap-based buffer overflow that can lead to full compromise of affected Office and Microsoft 365 client installs. Affected branches include Microsoft 365 Apps for Enterprise 16.0.1 through before 16.0.20326.20138 and multiple Office and LTSC 16.x releases listed by the vendor; the attacker requires only network access and no user interaction or credentials. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Microsoft 365 Apps for Enterprise are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft 365 Apps for Enterprise 16.x | 16.0.1 – before 16.0.20326.20138 | 16.0.20326.20138 |
| Microsoft Office 2019 16.x | 19.0.0 – before 16.0.10417.20207 | 16.0.10417.20207 |
| Microsoft Office 365 for Mac 16.x | 1.0.0 – before 16.113.26091433 | 16.113.26091433 |
| Microsoft Office LTSC 2021 16.x | 16.0.1 – before 16.0.14334.20906 | 16.0.14334.20906 |
| Microsoft Office LTSC 2024 16.x | 16.0.0 – before 16.0.17932.20976 | 16.0.17932.20976 |
| Microsoft Office LTSC for Mac 2021 16.x | 16.0.1 – before 16.113.26091433 | 16.113.26091433 |
| Microsoft Office LTSC for Mac 2024 16.x | 16.0.0 – before 16.113.26091433 | 16.113.26091433 |
| Microsoft Word 2016 16.x | 16.0.1 – before 16.0.5569.1000 | 16.0.5569.1000 |
Is CVE-2026-78509 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-78509
- Apply vendor updates to fixed builds listed by Microsoft (for example 16.0.20326.20138 for Microsoft 365 Apps for Enterprise and the corresponding fixed builds for Office and LTSC branches).
- Verify Microsoft Office and Microsoft 365 client versions and patch any installations older than the fixed versions in the vendor advisory.
- Restrict network exposure of vulnerable clients and block untrusted access to endpoints running affected Office components until updates are deployed.
- Monitor endpoints for unusual behavior and review logs for signs of remote code execution attempts.
Frequently asked questions
Is CVE-2026-78509 being actively exploited?
There are no public reports of exploitation as of 2026-09-30.
Which Microsoft 365 Apps versions are affected by CVE-2026-78509?
Microsoft 365 Apps for Enterprise and several Office/LTSC 16.x branches are affected; examples include 16.0.1 through before 16.0.20326.20138 for Microsoft 365 Apps for Enterprise and the fixed build 16.0.20326.20138.
Is there a patch for CVE-2026-78509?
Yes; Microsoft published fixed builds for each affected branch, including 16.0.20326.20138 for Microsoft 365 Apps for Enterprise and corresponding fixed versions for Office, Mac, and LTSC branches listed by the vendor.
Does CVE-2026-78509 require authentication?
No; the vulnerability permits unauthenticated remote code execution against affected Microsoft Office / Microsoft 365 client components.
References
- nvd.nist.gov/vuln/detail/CVE-2026-78509
- cve.org/CVERecord?id=CVE-2026-78509
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78509
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026