CVE-2026-78525 – Microsoft Office Outlook Remote Code Execution Vulnerability
CVSS 8.8
IMPORTANT
Critical - Same Day Deployment
“A malicious email can turn an Outlook message or preview into a path for remote code execution.”
CVE-2026-78525 is a Critical remote code execution vulnerability caused by a use-after-free weakness (CWE-416) in Microsoft Office Outlook. An unauthorized attacker can send a specially crafted email, and exploitation may occur when the victim opens the email using an affected Outlook version or when Outlook displays its preview. Successful exploitation could allow the attacker to execute remote code on the victim’s machine.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-416
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.