CVE-2026-78507 Advisory
Severity: HIGH (CVSS 8.8)
Affected Product:
- Microsoft Defender Business
Vulnerability Description: Use-after-free in Microsoft Office Word allows remote code execution without authentication.
KEV Status: Not currently listed as exploited in the wild
Remediation: Apply security updates from Microsoft Security Response Center: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78507
Recommendation: Prioritize patching given the high CVSS score and network-based attack vector. Monitor systems for suspicious Word document handling.