OVERCLOCK.news
security

CVE-2026-78525 Microsoft Office Outlook Remote Code Execution Vulnerability

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac.

BlueskyXRedditMail
Revised 1 change recorded since we first saw this
Microsoft 2 versions
  1. Current Summary changed

    4 new sentences, beginning: “Microsoft is announcing the availability of the security updates for Microsoft Office for Mac.”

    CVE-2026-78525 Microsoft Office Outlook Remote Code Execution Vulnerability

    Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links.

  2. As first published

    CVE-2026-78525 Microsoft Office Outlook Remote Code Execution Vulnerability

    Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Read the current version at Microsoft →

Versions are compared on the headline and summary the publisher puts in their feed. An edit to the body of an article that leaves both untouched will not appear here.

Why am I seeing this Ranked on source trust — Microsoft

It ranks mainly on source trust: Microsoft is the most reliable outlet we track on this subject, and is the only one on the story so far.

It clears the bar without leading strongly on any one factor. A middling score is not a claim that the story is important — only that nothing about it is weak.

StandardStandard, because a first-party source is on it, the subject was identified from the text, and it scores 0.49 against a bar of 0.50.

Blended score 0.494 — every figure below is computed, none of it is editorial.
FactorWeightScore ContributionWhere it came from
Corroboration 0.35 0.39 +0.135 27% 1 independent org on the story. Tier-3 aggregators never corroborate — they can show something is circulating, never that it is true.
Source trustleads 0.25 1.00 +0.250 51% Microsoft is the highest-trust source on this story and is first-party — the organisation announcing its own news. Trust is taken from the best source, not averaged.
Pickup rate 0.20 0.00 +0.000 0% One counted organisation, so there is no spread to measure — nothing has picked this up to set a rate.
Freshness 0.20 0.54 +0.109 22% Halves every 10 hours from the newest item on the story. This is the only factor that rewards a story for nothing more than being recent.

Corroboration counts distinct organisations, once each, and only from tiers 1 and 2. Freshness halves every 10 hours, so this ranking is a snapshot and will differ at the next build.

Read the full article at Microsoft →

What happened

Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not need to take any action. See the [Release Notes](https://go.microsoft.com/fwlink/p/?linkid=831049) for more information and download links. Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

1independent orgs
49story score
0velocity
100source trust
118passes seen
Moderate CVE-2026-78525

Limited impact or meaningful preconditions.

Impact
Remote Code Execution
Product
Microsoft Office Outlook

How this story arrived

Ordered by when each source was first observed, which is what the velocity figure is computed from. Publishers backdate; observed order does not.

  1. 01 Microsoftfirst-party first seen CVE-2026-78525 Microsoft Office Outlook Remote Code Execution Vulnerability

Overclock clusters coverage from independent sources and grades it automatically. The figures above are computed, not editorial. This page summarises and links to reporting by the outlets named — follow the links for the original work.