Description
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from use of an uninitialized resource within Microsoft Office Outlook, permitting an unauthorized attacker to execute arbitrary code. The weakness is classified as CWE-908, indicating a failure to correctly initialize a resource before use.

Affected Systems

Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Outlook 2016. Version details are not explicitly listed, so any installations of these products are potentially impacted.

Risk and Exploitability

The CVSS score of 8.8 places this flaw in the High severity range. EPSS is not available, but the absence of a KEV listing suggests that widespread exploitation has not yet been observed or catalogued. The description indicates that an unauthorized attacker can execute code over a network, implying the attack vector is network-based. No further details are reported about prerequisites or specific conditions.

Generated by OpenCVE AI on September 9, 2026 at 03:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security updates listed in the Microsoft update guide for the affected Office and Outlook products
  • Restrict Office application exposure so that only authenticated users on trusted networks can launch Outlook or Office components
  • Configure monitoring and intrusion detection to alert on abnormal Office traffic or unexpected code execution events

Generated by OpenCVE AI on September 9, 2026 at 03:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Office 2016
Microsoft microsoft Office 2019
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024
Vendors & Products Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Office 2016
Microsoft microsoft Office 2019
Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft outlook
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:x86:*
Vendors & Products Microsoft outlook

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Title Microsoft Office Outlook Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft outlook 2016
Weaknesses CWE-908
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:outlook_2016:*:*:*:*:*:x86:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft outlook 2016
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Apps For Enterprise Microsoft Office 2016 Microsoft Office 2019 Microsoft Office Ltsc 2021 Microsoft Office Ltsc 2024 Office 2019 Office 2021 Office 2024 Outlook Outlook 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:22.859Z

Reserved: 2026-08-24T17:28:00.622Z

Link: CVE-2026-78519

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:12.965Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:47.427

Modified: 2026-09-09T18:58:55.107

Link: CVE-2026-78519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:35Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource