Microsoft Office Word: 25 Memory Corruption Vulnerabilities Disclosed Together
Microsoft Office Word: 25 vulnerabilities, including critical remote code execution flaws, disclosed in a single batch on September 8, 2026.

Key findings
- Microsoft Office Word: 25 vulnerabilities disclosed on September 8, 2026, including one critical heap-based buffer overflow.
- Flaws include heap and stack buffer overflows, double frees, use-after-free, and out-of-bounds reads.
- Vulnerabilities range in severity from medium (information disclosure) to critical (remote code execution).
- These vulnerabilities were part of Microsoft's record-breaking September 2026 Patch Tuesday release.
- Users are urged to update Microsoft Office Word to the latest version to patch these issues.
On September 8, 2026, Microsoft released a significant security update addressing 25 vulnerabilities in Microsoft Office Word. This batch of CVEs, disclosed on the same day, includes a critical heap-based buffer overflow and several high-severity flaws, alongside medium-severity issues. The vulnerabilities primarily involve memory corruption, such as buffer overflows, double frees, and use-after-free errors, with potential impacts ranging from local information disclosure to remote code execution over a network.
The disclosed vulnerabilities can be broadly categorized by their impact and underlying vulnerability class:
Remote Code Execution Vulnerabilities (High and Critical Severity)
A notable portion of this batch consists of vulnerabilities that allow for remote code execution, posing the most significant threat. These include:
- Heap-based Buffer Overflows: CVE-2026-81952, CVE-2026-80085, CVE-2026-78526, CVE-2026-78521, CVE-2026-78517, CVE-2026-78511, CVE-2026-78510 (Critical severity), and CVE-2026-78504. These flaws allow attackers to overwrite memory on the heap, potentially leading to code execution.
- Double Free Vulnerabilities: CVE-2026-80080 and CVE-2026-77504. These vulnerabilities arise from freeing the same memory region twice, which can corrupt heap metadata and lead to code execution.
- Use After Free Vulnerabilities: CVE-2026-78514 and CVE-2026-78507. These occur when a program attempts to access memory after it has been freed, leading to unpredictable behavior and potential code execution.
- Other Remote Code Execution Flaws: CVE-2026-78512 (Numeric truncation error), CVE-2026-77901 (Null pointer dereference), and CVE-2026-78504 (Stack-based buffer overflow).
Information Disclosure Vulnerabilities (Medium Severity)
Several medium-severity vulnerabilities were also disclosed, primarily involving buffer over-reads and out-of-bounds reads. These flaws allow attackers to read sensitive memory contents, potentially leading to information disclosure.
- Buffer Over-reads: CVE-2026-83951 and CVE-2026-83949. These vulnerabilities allow attackers to read more data than intended from a buffer, potentially exposing sensitive information.
- Out-of-Bounds Reads: CVE-2026-80090, CVE-2026-80088, CVE-2026-78522, CVE-2026-78503, CVE-2026-77911, and CVE-2026-72976. These flaws permit attackers to read data beyond the intended boundaries of a buffer, leading to information disclosure.
- Improper Null Termination: CVE-2026-78506. This vulnerability can lead to reading beyond the intended end of a string, potentially disclosing sensitive information.
Exploitation and Response
Microsoft's September 2026 Patch Tuesday update addressed a record-breaking number of vulnerabilities, with 974 CVEs in total. Among these, two zero-day vulnerabilities were reported to be under active exploitation. While the provided information does not explicitly state that any of the Office Word vulnerabilities in this specific batch were exploited in the wild, the presence of critical and high-severity flaws, particularly those allowing remote code execution, indicates a significant risk to users.
The related news coverage highlights the sheer volume of the September 2026 Patch Tuesday release, with sources like CrowdStrike, Cisco Talos, Rapid7, Dark Reading, and Cyber Security News reporting on the extensive list of fixes. Notably, CVE-2026-77504, CVE-2026-78510, and CVE-2026-81952 are mentioned in relation to the overall Patch Tuesday release, with CVE-2026-78510 being specifically called out by Dark Reading as a high-priority vulnerability. Rapid7 and Cyber Security News list the majority of the Office Word CVEs in this batch, indicating their inclusion in the broader security update. Microsoft has released patches for all these vulnerabilities, and users are strongly advised to update their Microsoft Office Word installations to the latest versions to mitigate these risks.
This coordinated disclosure of 25 vulnerabilities in Microsoft Office Word underscores the ongoing efforts by Microsoft to address security weaknesses in its widely used productivity suite. Users should prioritize applying these security updates to protect against potential exploitation of these memory corruption vulnerabilities. The sheer number of vulnerabilities patched on this day emphasizes the importance of timely patching and robust security practices for all Microsoft products.
CVE-2026-83951, CVE-2026-83949, CVE-2026-81952, CVE-2026-80090, CVE-2026-80088, CVE-2026-80085, CVE-2026-80080, CVE-2026-80079, CVE-2026-78526, CVE-2026-78522, CVE-2026-78521, CVE-2026-78517, CVE-2026-78514, CVE-2026-78512, CVE-2026-78511, CVE-2026-78510, CVE-2026-78507, CVE-2026-78506, CVE-2026-78504, CVE-2026-78503, CVE-2026-78502, CVE-2026-77911, CVE-2026-77901, CVE-2026-77504, CVE-2026-72976