Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. To exploit the vulnerability, an attacker must first convince a user to open a specially crafted Office document. The updates address the vulnerability by correcting how Office validates input before loading DLL files. | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| Title | Microsoft Office Remote Code Execution Vulnerability | Microsoft Outlook and Word Remote Code Execution Vulnerability |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 24 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. To exploit the vulnerability, an attacker must first convince a user to open a specially crafted Office document. The updates address the vulnerability by correcting how Office validates input before loading DLL files. |
| Title | Microsoft Outlook and Word Remote Code Execution Vulnerability | Microsoft Office Remote Code Execution Vulnerability |
Mon, 21 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. |
| Title | Microsoft Word Remote Code Execution Vulnerability | Microsoft Outlook and Word Remote Code Execution Vulnerability |
Wed, 09 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft microsoft 365
|
|
| CPEs | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:* cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:* cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:* cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x64:* cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x86:* cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:* cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:* cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:* cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:* cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:* cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:* cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:* cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:* |
|
| Vendors & Products |
Microsoft microsoft 365
|
Tue, 08 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |
| Title | Microsoft Word Remote Code Execution Vulnerability | |
| First Time appeared |
Microsoft
Microsoft 365 Apps Microsoft office 2016 Microsoft office 2019 Microsoft office 2021 Microsoft office 2024 Microsoft office 365 Microsoft office Macos 2021 Microsoft office Macos 2024 |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:* cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:* cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:* cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:* cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:* cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:* |
|
| Vendors & Products |
Microsoft
Microsoft 365 Apps Microsoft office 2016 Microsoft office 2019 Microsoft office 2021 Microsoft office 2024 Microsoft office 365 Microsoft office Macos 2021 Microsoft office Macos 2024 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-09-25T21:33:38.838Z
Reserved: 2026-08-24T17:28:00.622Z
Link: CVE-2026-78510
Updated: 2026-09-09T10:00:27.392Z
Status : Modified
Published: 2026-09-08T18:20:46.200
Modified: 2026-09-25T22:18:36.710
Link: CVE-2026-78510
No data.
OpenCVE Enrichment
Updated: 2026-09-26T05:45:05Z
-
CWE-122
Heap-based Buffer Overflow