CVE-2026-78520 – Microsoft Office Outlook Information Disclosure Vulnerability
CVSS 6.5
MODERATE
Critical - Same Day Deployment
“A malicious Outlook item can expose sensitive memory simply through the Preview Pane, turning routine email handling into a potential data exposure risk.”
CVE-2026-78520 is a Microsoft Office Outlook vulnerability caused by an out-of-bounds read. An unauthorized remote attacker can target the vulnerability over a network, and exploitation requires user interaction. Microsoft confirms that the Outlook Preview Pane is an attack vector. Successful exploitation could allow an attacker to read small portions of heap memory, potentially exposing sensitive information stored in memory.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-125
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.