CVE
CVE-2026-78517
0field notes · 1digest CVSS 8.8
The verdict
An attacker can send a malicious Word document that triggers a heap buffer overflow, giving them code execution on the victim's machine over the network. The victim needs to open the file, but no elevated privileges are required on the attacker's side. This hits Microsoft 365 Apps, Office 2019, and Office 365 for Mac.
Patch urgency · Patch this week
Daily digests