CVE-2026-78510 – Microsoft Office Outlook Remote Code Execution Vulnerability
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“A malicious RTF file can turn Outlook content into a path for remote code execution, with no privileges or user interaction required.”
CVE-2026-78510 is a critical heap-based buffer overflow vulnerability in Microsoft Office Outlook that can allow an unauthenticated attacker to execute arbitrary code over a network. An attacker can craft a malicious RTF file that triggers the vulnerability when opened or rendered in the Preview Pane. Successful exploitation can compromise confidentiality, integrity, and availability with code executing in the user’s context.
Key Details
- Affected Product
- Microsoft 365 Apps
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-122
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.