Junglewise Threat Intelligence

CVE-2026-78512: Microsoft Office Word numeric truncation remote code execution

CVE-2026-78512 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Word is a widely-used word processing application found in millions of PCs and business environments. A numeric truncation error in Word can be exploited by an attacker to execute arbitrary code on a user's computer, potentially leading to data theft, malware installation, or system compromise.

Technical details

A numeric truncation error in Microsoft Office Word's document parsing logic allows remote code execution. An attacker can craft a malicious Word document that, when opened by a victim, triggers the vulnerability through a network-accessible mechanism. The vulnerability permits unauthenticated remote code execution with no reported user interaction bypass requirement. No patch availability information is currently confirmed in the provided advisory text.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats