CVE-2026-78525 – Microsoft Office Outlook Remote Code Execution Vulnerability

CVSS 8.8 IMPORTANT Critical - Same Day Deployment

“A malicious email can turn an Outlook message or preview into a path for remote code execution.”

CVE-2026-78525 is a Critical remote code execution vulnerability caused by a use-after-free weakness (CWE-416) in Microsoft Office Outlook. An unauthorized attacker can send a specially crafted email, and exploitation may occur when the victim opens the email using an affected Outlook version or when Outlook displays its preview. Successful exploitation could allow the attacker to execute remote code on the victim’s machine.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.