CVE-2026-78506 Advisory
Severity: MEDIUM (CVSS 5.5)
Affected Product:
- Microsoft Defender Business
Vulnerability Description: Improper null termination in Microsoft Office Word allows unauthorized local information disclosure.
KEV Status: Not currently listed as exploited in the wild.
Remediation:
- Apply security updates from Microsoft
- Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78506
Impact: Local attacker could disclose sensitive information. No network exploitation vector.