CVE-2026-77901 Advisory
Severity: HIGH (CVSS 8.8)
Affected Product:
- Microsoft Defender Business
Vulnerability Description: Null pointer dereference in Microsoft Office Word allows remote code execution over a network without authentication.
KEV Status: Not currently listed as exploited in known exploited vulnerabilities catalog.
Remediation: Apply security updates from Microsoft. Refer to the official advisory for specific patch availability and deployment guidance.
Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77901