Junglewise Threat Intelligence

CVE-2026-81385: Microsoft Office Publisher deserialization code execution

CVE-2026-81385 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Publisher is a desktop application used to create and distribute marketing materials and publications. A flaw in how it processes document files allows an attacker to craft a malicious document that executes arbitrary code on a user's computer when opened. An attacker can distribute this document via email or website to compromise systems and steal data or install malware.

Technical details

The vulnerability is a deserialization of untrusted data flaw in Microsoft Office Publisher. When a user opens a specially crafted document file, the application deserializes attacker-controlled data without proper validation, allowing arbitrary code execution. The attack vector is network-based (via document delivery), but requires user interaction to open the malicious file. An authenticated user is not required. A successful exploit grants the attacker code execution in the context of the user running Publisher, potentially allowing full system compromise.

Affected products

  • Microsoft Office Publisher

Timeline

  • 2026-09-08: disclosed

References

Related threats