CVE-2026-78512 Advisory
Severity: HIGH (CVSS 8.8)
Affected Product:
- Microsoft Defender Business
Vulnerability Description: Numeric truncation error in Microsoft Office Word allows remote code execution over a network.
KEV Status: Not currently listed in CISA’s Known Exploited Vulnerabilities catalog.
Remediation:
- Review Microsoft Security Response Center (MSRC) update guidance at: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78512
- Apply security updates for Microsoft Defender Business as released by Microsoft
- Restrict network access to affected systems where feasible pending patching
Recommendation: Prioritize patching due to HIGH severity and remote exploitation capability. Monitor CISA KEV for exploitation indicators.