Junglewise Threat Intelligence

CVE-2026-78526: Microsoft Office Word heap-based buffer overflow

CVE-2026-78526 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Word is widely used for document creation and editing across organizations. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer by sending a specially crafted document over a network, potentially leading to data theft, system compromise, or lateral movement within corporate networks.

Technical details

A heap-based buffer overflow exists in Microsoft Office Word's document processing logic. The vulnerability occurs when Word processes a maliciously crafted document, allowing an attacker to write beyond allocated heap memory bounds. An attacker can exploit this remotely by sending a specially crafted Word document (e.g., via email or network share) without requiring user authentication beyond opening the file. Successful exploitation enables remote code execution with the privileges of the user running Word. Patches are expected to be available from Microsoft through their regular security update cycle.

Affected products

  • Microsoft Office Word <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats