Junglewise Threat Intelligence

CVE-2026-80078: Microsoft Office out-of-bounds read

CVE-2026-80078 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office contains an out-of-bounds read vulnerability that allows an attacker to disclose sensitive information through a network connection. An attacker can exploit this flaw to read data from memory that should not be accessible, potentially exposing confidential documents or user information. No active exploitation in the wild has been reported.

Technical details

The vulnerability is an out-of-bounds read in Microsoft Office, a memory safety issue where the application reads data beyond the boundaries of allocated memory. This flaw can be triggered over a network, allowing an unauthenticated attacker to craft a malicious Office document or network message that causes the application to leak sensitive data from process memory. The vulnerability enables information disclosure but does not directly allow code execution or unauthorized modification. Microsoft has issued security updates to address this issue.

Affected products

  • Microsoft Office

Timeline

  • 2026-09-08: disclosed

References

Related threats