CVE-2026-78439: Microsoft Office 365 For Mac

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Affected products

  • Microsoft Microsoft Office 365 For Mac: from 1.0.0, before 16.113.26091433 (fixed in 16.113.26091433)
  • Microsoft Microsoft Office For Android: from 16.0.1, before 16.0.20430.20000 (fixed in 16.0.20430.20000)
  • Microsoft Microsoft Office Ltsc For Mac 2021: from 16.0.1, before 16.113.26091433 (fixed in 16.113.26091433)
  • Microsoft Microsoft Office Ltsc For Mac 2024: from 16.0.0, before 16.113.26091433 (fixed in 16.113.26091433)

Published 2026-09-08. Last modified 2026-09-17.