CVE-2026-78509 – Microsoft Office Outlook Remote Code Execution Vulnerability
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“A specially crafted email could turn simply viewing a message into remote code execution, with no clicks or user action required.”
CVE-2026-78509 is a Critical heap-based buffer overflow vulnerability in Microsoft Office Outlook that could allow an unauthorized remote attacker to execute code on a target system. An attacker can send a specially crafted email, and simply viewing it in the Outlook Reading Pane can trigger the vulnerability without opening the message or clicking anything. The CVSS base score is 9.8, and exploitation requires neither authentication nor user interaction.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-122
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.