PatchDayAlert

CVE

CVE-2026-78517

0field notes · 1digest CVSS 8.8

The verdict

An attacker can send a malicious Word document that triggers a heap buffer overflow, giving them code execution on the victim's machine over the network. The victim needs to open the file, but no elevated privileges are required on the attacker's side. This hits Microsoft 365 Apps, Office 2019, and Office 365 for Mac.

Patch urgency · Patch this week


Daily digests