Junglewise Threat Intelligence

CVE-2026-78521: Microsoft Office Word heap-based buffer overflow

CVE-2026-78521 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Word is widely used for document creation and editing across organizations. A heap-based buffer overflow vulnerability in Word allows an attacker to execute arbitrary code by sending a specially crafted document over the network, potentially compromising user systems and exposing sensitive business data.

Technical details

A heap-based buffer overflow exists in Microsoft Office Word that can be triggered by a specially crafted document. The vulnerability is reachable over the network without requiring user authentication to the affected system, though user interaction (opening a malicious document) is typically required. An attacker can exploit this flaw to achieve remote code execution with the privileges of the user running Word. The vulnerability has a CVSS score of 8.8, indicating high severity, though no active exploitation in the wild has been reported as of the publication date.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-09-08: disclosed

References

Related threats