VYPR
Vypr IntelligenceAI-generatedSep 8, 2026· 25 CVEs

Microsoft Office Word: 25 Memory Corruption Vulnerabilities Disclosed Together

Microsoft Office Word: 25 vulnerabilities, including critical remote code execution flaws, disclosed in a single batch on September 8, 2026.

Key findings

  • Microsoft Office Word: 25 vulnerabilities disclosed on September 8, 2026, including one critical heap-based buffer overflow.
  • Flaws include heap and stack buffer overflows, double frees, use-after-free, and out-of-bounds reads.
  • Vulnerabilities range in severity from medium (information disclosure) to critical (remote code execution).
  • These vulnerabilities were part of Microsoft's record-breaking September 2026 Patch Tuesday release.
  • Users are urged to update Microsoft Office Word to the latest version to patch these issues.

On September 8, 2026, Microsoft released a significant security update addressing 25 vulnerabilities in Microsoft Office Word. This batch of CVEs, disclosed on the same day, includes a critical heap-based buffer overflow and several high-severity flaws, alongside medium-severity issues. The vulnerabilities primarily involve memory corruption, such as buffer overflows, double frees, and use-after-free errors, with potential impacts ranging from local information disclosure to remote code execution over a network.

The disclosed vulnerabilities can be broadly categorized by their impact and underlying vulnerability class:

Remote Code Execution Vulnerabilities (High and Critical Severity)

A notable portion of this batch consists of vulnerabilities that allow for remote code execution, posing the most significant threat. These include:

Information Disclosure Vulnerabilities (Medium Severity)

Several medium-severity vulnerabilities were also disclosed, primarily involving buffer over-reads and out-of-bounds reads. These flaws allow attackers to read sensitive memory contents, potentially leading to information disclosure.

Exploitation and Response

Microsoft's September 2026 Patch Tuesday update addressed a record-breaking number of vulnerabilities, with 974 CVEs in total. Among these, two zero-day vulnerabilities were reported to be under active exploitation. While the provided information does not explicitly state that any of the Office Word vulnerabilities in this specific batch were exploited in the wild, the presence of critical and high-severity flaws, particularly those allowing remote code execution, indicates a significant risk to users.

The related news coverage highlights the sheer volume of the September 2026 Patch Tuesday release, with sources like CrowdStrike, Cisco Talos, Rapid7, Dark Reading, and Cyber Security News reporting on the extensive list of fixes. Notably, CVE-2026-77504, CVE-2026-78510, and CVE-2026-81952 are mentioned in relation to the overall Patch Tuesday release, with CVE-2026-78510 being specifically called out by Dark Reading as a high-priority vulnerability. Rapid7 and Cyber Security News list the majority of the Office Word CVEs in this batch, indicating their inclusion in the broader security update. Microsoft has released patches for all these vulnerabilities, and users are strongly advised to update their Microsoft Office Word installations to the latest versions to mitigate these risks.

This coordinated disclosure of 25 vulnerabilities in Microsoft Office Word underscores the ongoing efforts by Microsoft to address security weaknesses in its widely used productivity suite. Users should prioritize applying these security updates to protect against potential exploitation of these memory corruption vulnerabilities. The sheer number of vulnerabilities patched on this day emphasizes the importance of timely patching and robust security practices for all Microsoft products.

CVE-2026-83951, CVE-2026-83949, CVE-2026-81952, CVE-2026-80090, CVE-2026-80088, CVE-2026-80085, CVE-2026-80080, CVE-2026-80079, CVE-2026-78526, CVE-2026-78522, CVE-2026-78521, CVE-2026-78517, CVE-2026-78514, CVE-2026-78512, CVE-2026-78511, CVE-2026-78510, CVE-2026-78507, CVE-2026-78506, CVE-2026-78504, CVE-2026-78503, CVE-2026-78502, CVE-2026-77911, CVE-2026-77901, CVE-2026-77504, CVE-2026-72976

AI-written article. Grounded in 25 CVE records listed below.