CVE-2026-78509: Microsoft Office Vulnerability with CVSS 9.8
This text was generated using artificial intelligence (AI).Microsoft introduces CVE-2026-78509 with a CVSS score of 9.8. The vulnerability affects several Microsoft Office products. The CVSS score describes a network-based attack vector with low complexity, requiring no authentication and no user interaction.
According to the Microsoft Security Response Center advisory on CVE-2026-78509, the vulnerability affects the following products — the complete and authoritative product list should be verified directly in the MSRC advisory:
Microsoft 365 Apps for Enterprise
Microsoft Office 2019
Microsoft Office 365 for Mac
Microsoft Office LTSC 2021
Microsoft Office LTSC 2024
Microsoft Office LTSC for Mac 2021
Microsoft Office LTSC for Mac 2024
Microsoft Word 2016
For confidentiality, integrity, and availability, the CVSS score indicates high impact. No active exploitation is documented for CVE-2026-78509.
Check patch status and impact
Organizations should map the affected products in their software inventory and check the patch status for CVE-2026-78509. For the mentioned Microsoft Office and Word products, the updates from the September 2026 Patch Tuesday must be installed.
Structured processing includes in particular:
Discover Microsoft 365 Apps, Office 2019, Office LTSC editions, and Word 2016 in the inventory.
Compare the update status of the deployed products with the information in the Microsoft Update Guide.
Prioritize and mitigate affected systems.
Establish current patch levels for the affected systems.
Integrate the assessment into continuous vulnerability and vendor risk monitoring.
For organizations in Germany and Austria that fall under the NIS-2 Directive, structured vulnerability management is part of the legal duty of care; in Switzerland, the revised Information Security Act (ISA) applies with a reporting obligation to BACS. If successful exploitation of this vulnerability leads to a data protection incident involving personal data, there is a 72-hour reporting obligation to the competent data protection authority in accordance with Article 33 of the GDPR.
Visibility of publicly accessible services
Checking installed Office products and their patch levels remains a task for the internal software inventory. LocateRisk can make publicly accessible services and product traces visible under owned domains. This visibility can assist with prioritization, but it does not confirm a specifically vulnerable version.
For the supplier perspective, C-VRM complements the technical assessment: it can report when critical vulnerabilities become known at technology providers or when their security level changes. This allows vendor lock-in and dependencies to be included in the risk assessment.
Am I affected?
Affected are Microsoft 365 Apps for Enterprise, Microsoft Office 2019, and Microsoft Office 365 for Mac. Anyone who wants to know whether Microsoft 365 Apps for Enterprise, Microsoft Office 2019, and Microsoft Office 365 for Mac are even visible in their own externally accessible infrastructure can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-78509 is a critical vulnerability in multiple Microsoft Office products that enables Remote Code Execution. The CVSS score is 9.8 — the highest criticality level on the CVSS 3.1 scale. Microsoft released security updates on September 8, 2026, as part of Patch Tuesday.
According to the Microsoft Security Response Center, multiple Microsoft Office product families are affected, including Microsoft 365 Apps for Enterprise, Office 2019, various LTSC editions, and Word 2016. The binding and complete product list can be viewed directly in the MSRC advisory. As of the time of publication, no active exploitation has been documented for CVE-2026-78509.
Microsoft released security updates as part of Patch Tuesday on September 8, 2026. Organizations should inventory affected products, cross-reference their patch status with the Microsoft Update Guide, and deploy pending updates promptly. Subsequently, integration into continuous vulnerability monitoring is recommended.
As of September 9, 2026. This post is for general informational purposes and does not constitute legal, security, or operational advice in individual cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we assume no liability for timeliness, accuracy, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-78509
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.