CVE-2026-78510
Microsoft Word Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowThis is a critical Microsoft Word security flaw that can let an attacker run code just by reaching a vulnerable Word setup, so most businesses using Microsoft Office or Microsoft 365 Apps should act quickly to install the fixed updates.
CVE-2026-78510 is a Microsoft Word remote code execution issue caused by a heap-based buffer overflow (CWE-122), allowing an unauthorized attacker to execute code via network access against affected Microsoft Office/Microsoft 365 desktop installations.
What to do now
- Check which Microsoft Office/Microsoft 365 apps version you’re running (Windows or Mac) and whether it falls before the fixed versions listed by Microsoft for CVE-2026-78510.
- If you’re on Microsoft 365 Apps, update Word to 16.0.20326.20138 or later.
- If you’re on Microsoft Office (including Office 2016/2019/2021/2024 and Mac variants listed), update to the Microsoft-fixed 16.0.5569.1000 / 16.0.10417.20207 / 16.0.14334.20906 / 16.0.17932.20976 version that matches your branch.
- Restart Office after updating, then confirm the new version number appears in the Office app’s “About” screen.
- If you cannot update immediately, restrict exposure by reducing inbound access to Office-related endpoints and tighten email/file handling until updates are applied.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Patch Tuesday Sets Another Record With 974 CVEsen·Dark Reading· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-78510 and every CVE in our database. Create a free account — no credit card required.
Create Free Account