Microsoft assigned CVE-2026-78517 a CVSS base score of 8.8 and a temporal score of 7.7. Its complete vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C. In practical terms, an attacker does not need an account or elevated privileges, but must persuade the target to open a crafted Office document.
Publicly disclosed: No
Exploited: No
Customer action required: Yes
Microsoft’s exploitation assessment is Exploitation Less Likely. That assessment should not delay patching: successful exploitation can affect confidentiality, integrity, and availability, as reflected in the high C, I, and A impacts in the CVSS vector.
Opening a malicious Office file is required
Microsoft’s advisory describes the issue as follows: “Microsoft Office Word Remote Code Execution Vulnerability: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.”
The required user interaction is specific. An attacker must send a user a malicious Office file and convince them to open it. Microsoft also states that the Preview Pane is not an attack vector for this vulnerability. Merely selecting a suspicious file in a preview workflow is therefore not the documented trigger; opening the crafted Office file is.
Organizations should still treat unexpected documents as suspicious, especially files delivered through email or external file-sharing channels. User caution is a useful exposure reduction measure, but it does not replace applying the supplied security update.
Fixed builds for Windows Office installations
Microsoft’s remediation is build-specific. Administrators should ensure each deployed product reaches the fixed build listed below or a later build.
| Affected product | Required remediation | Fixed build / KB |
|---|---|---|
| Microsoft 365 Apps for Enterprise for 32-bit Systems (x86) | For Microsoft 365 Apps for Enterprise for 32-bit Systems (x86), update to fixed build 16.0.20326.20138 or later. | 16.0.20326.20138 |
| Microsoft 365 Apps for Enterprise for 64-bit Systems (x64) | For Microsoft 365 Apps for Enterprise for 64-bit Systems (x64), update to fixed build 16.0.20326.20138 or later. | 16.0.20326.20138 |
| Microsoft Office 2019 for 32-bit editions (x86) | For Microsoft Office 2019 for 32-bit editions (x86), update to fixed build 16.0.10417.20207 or later. | 16.0.10417.20207 |
| Microsoft Office 2019 for 64-bit editions (x64) | For Microsoft Office 2019 for 64-bit editions (x64), update to fixed build 16.0.10417.20207 or later. | 16.0.10417.20207 |
| Microsoft Office LTSC 2021 for 32-bit editions (x86) | For Microsoft Office LTSC 2021 for 32-bit editions (x86), update to fixed build 16.0.14334.20906 or later. | 16.0.14334.20906 |
| Microsoft Office LTSC 2021 for 64-bit editions (x64) | For Microsoft Office LTSC 2021 for 64-bit editions (x64), update to fixed build 16.0.14334.20906 or later. | 16.0.14334.20906 |
| Microsoft Office LTSC 2024 for 32-bit editions (x86) | For Microsoft Office LTSC 2024 for 32-bit editions (x86), update to fixed build 16.0.17932.20976 or later. | 16.0.17932.20976 |
| Microsoft Office LTSC 2024 for 64-bit editions (x64) | For Microsoft Office LTSC 2024 for 64-bit editions (x64), update to fixed build 16.0.17932.20976 or later. | 16.0.17932.20976 |
| Microsoft Word 2016 (32-bit edition) (x86) | For Microsoft Word 2016 (32-bit edition) (x86), install KB5002923 to reach fixed build 16.0.5569.1000. | KB5002923 / 16.0.5569.1000 |
| Microsoft Word 2016 (64-bit edition) (x64) | For Microsoft Word 2016 (64-bit edition) (x64), install KB5002923 to reach fixed build 16.0.5569.1000. | KB5002923 / 16.0.5569.1000 |
The key distinction for managed environments is that Microsoft 365 Apps for Enterprise, Office 2019, and Office LTSC releases have different fixed-version thresholds. Inventory and compliance reporting should therefore compare installed builds against the applicable product row rather than using one build number across the Office estate.
Mac builds are available
Microsoft confirms that, as of September 16, 2026, security updates were available for Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office 365 for Mac. Customers using these products should ensure that the update is installed.
| Affected product | Required remediation | Fixed build |
|---|---|---|
| Microsoft Office 365 for Mac | For Microsoft Office 365 for Mac, update to fixed build 16.113.26091433 or later. | 16.113.26091433 |
| Microsoft Office LTSC for Mac 2021 | For Microsoft Office LTSC for Mac 2021, update to fixed build 16.113.26091433 or later. | 16.113.26091433 |
| Microsoft Office LTSC for Mac 2024 | For Microsoft Office LTSC for Mac 2024, update to fixed build 16.113.26091433 or later. | 16.113.26091433 |
For IT teams, the immediate task is to identify which Office product family and architecture each device runs, deploy the applicable update, and confirm the reported version meets or exceeds Microsoft’s fixed build. Users awaiting deployment should avoid opening unexpected Office documents, particularly files sent by unfamiliar or unverified senders.