CVE-2026-78510 Advisory
Severity: CRITICAL (CVSS 9.8)
Affected Product:
- Microsoft Defender Business
Vulnerability: Heap-based buffer overflow in Microsoft Office Word permits remote code execution without authentication.
KEV Status: Not currently listed as exploited in the wild.
Remediation:
- Apply security updates from Microsoft: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78510
- Prioritize patching given critical CVSS score and network-exploitable vector
Action: Monitor for updates and deploy patches urgently to all affected systems.