Microsoft has published CVE-2026-78517, Microsoft Office Word Remote Code Execution Vulnerability, an Important Office security issue that requires customers to update affected Word and Office installations. The vulnerability is a heap-based buffer overflow, tracked as CWE-122, that allows an unauthorized attacker to execute code over a network when a user opens a malicious Office file.

Microsoft assigned CVE-2026-78517 a CVSS base score of 8.8 and a temporal score of 7.7. Its complete vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C. In practical terms, an attacker does not need an account or elevated privileges, but must persuade the target to open a crafted Office document.

Publicly disclosed: No

Exploited: No

Customer action required: Yes

Microsoft’s exploitation assessment is Exploitation Less Likely. That assessment should not delay patching: successful exploitation can affect confidentiality, integrity, and availability, as reflected in the high C, I, and A impacts in the CVSS vector.

Opening a malicious Office file is required​

Microsoft’s advisory describes the issue as follows: “Microsoft Office Word Remote Code Execution Vulnerability: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.”

The required user interaction is specific. An attacker must send a user a malicious Office file and convince them to open it. Microsoft also states that the Preview Pane is not an attack vector for this vulnerability. Merely selecting a suspicious file in a preview workflow is therefore not the documented trigger; opening the crafted Office file is.

Organizations should still treat unexpected documents as suspicious, especially files delivered through email or external file-sharing channels. User caution is a useful exposure reduction measure, but it does not replace applying the supplied security update.


Fixed builds for Windows Office installations​

Microsoft’s remediation is build-specific. Administrators should ensure each deployed product reaches the fixed build listed below or a later build.

Affected productRequired remediationFixed build / KB
Microsoft 365 Apps for Enterprise for 32-bit Systems (x86)For Microsoft 365 Apps for Enterprise for 32-bit Systems (x86), update to fixed build 16.0.20326.20138 or later.16.0.20326.20138
Microsoft 365 Apps for Enterprise for 64-bit Systems (x64)For Microsoft 365 Apps for Enterprise for 64-bit Systems (x64), update to fixed build 16.0.20326.20138 or later.16.0.20326.20138
Microsoft Office 2019 for 32-bit editions (x86)For Microsoft Office 2019 for 32-bit editions (x86), update to fixed build 16.0.10417.20207 or later.16.0.10417.20207
Microsoft Office 2019 for 64-bit editions (x64)For Microsoft Office 2019 for 64-bit editions (x64), update to fixed build 16.0.10417.20207 or later.16.0.10417.20207
Microsoft Office LTSC 2021 for 32-bit editions (x86)For Microsoft Office LTSC 2021 for 32-bit editions (x86), update to fixed build 16.0.14334.20906 or later.16.0.14334.20906
Microsoft Office LTSC 2021 for 64-bit editions (x64)For Microsoft Office LTSC 2021 for 64-bit editions (x64), update to fixed build 16.0.14334.20906 or later.16.0.14334.20906
Microsoft Office LTSC 2024 for 32-bit editions (x86)For Microsoft Office LTSC 2024 for 32-bit editions (x86), update to fixed build 16.0.17932.20976 or later.16.0.17932.20976
Microsoft Office LTSC 2024 for 64-bit editions (x64)For Microsoft Office LTSC 2024 for 64-bit editions (x64), update to fixed build 16.0.17932.20976 or later.16.0.17932.20976
Microsoft Word 2016 (32-bit edition) (x86)For Microsoft Word 2016 (32-bit edition) (x86), install KB5002923 to reach fixed build 16.0.5569.1000.KB5002923 / 16.0.5569.1000
Microsoft Word 2016 (64-bit edition) (x64)For Microsoft Word 2016 (64-bit edition) (x64), install KB5002923 to reach fixed build 16.0.5569.1000.KB5002923 / 16.0.5569.1000

The key distinction for managed environments is that Microsoft 365 Apps for Enterprise, Office 2019, and Office LTSC releases have different fixed-version thresholds. Inventory and compliance reporting should therefore compare installed builds against the applicable product row rather than using one build number across the Office estate.

Mac builds are available​

Microsoft confirms that, as of September 16, 2026, security updates were available for Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Office 365 for Mac. Customers using these products should ensure that the update is installed.

Affected productRequired remediationFixed build
Microsoft Office 365 for MacFor Microsoft Office 365 for Mac, update to fixed build 16.113.26091433 or later.16.113.26091433
Microsoft Office LTSC for Mac 2021For Microsoft Office LTSC for Mac 2021, update to fixed build 16.113.26091433 or later.16.113.26091433
Microsoft Office LTSC for Mac 2024For Microsoft Office LTSC for Mac 2024, update to fixed build 16.113.26091433 or later.16.113.26091433

For IT teams, the immediate task is to identify which Office product family and architecture each device runs, deploy the applicable update, and confirm the reported version meets or exceeds Microsoft’s fixed build. Users awaiting deployment should avoid opening unexpected Office documents, particularly files sent by unfamiliar or unverified senders.