CVE-2026-78520
Ein Angreifer kann mehrere Schwachstellen in verschiedenen Microsoft Office Produkten, Microsoft Office Online Server, Microsoft 365 Apps, Microsoft SharePoint, Microsoft Teams und Microsoft Skype ausnutzen, um erhöhte Berechtigungen zu erlangen, um Code auszuführen, um Informationen offenzulegen und um den Nutzer zu täuschen.
⚡ Watch CVE-2026-78520
Get an email if CVE-2026-78520 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEU] [hoch] Microsoft Office Produkte: Mehrere Schwachstellencert-bund · 2026-09-09
- mediumCVE-2026-78520: Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code…nvd · 2026-09-08
- mediumCVE-2026-78520: Microsoft Office Outlook Information Disclosure Vulnerabilitymsrc · 2026-09-08
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-78520)