Skip to content
Haifei Li on X: "This Microsoft Patch Tuesday, among with the historical 974 (!) bugs patched, I ...

Haifei Li on X: "This Microsoft Patch Tuesday, among with the historical 974 (!) bugs patched, I ...

X September 8, 2026

This Microsoft Patch Tuesday, among with the historical 974 (!) bugs patched, I contributed three.

- Microsoft Word Remote Code Execution Vulnerability (CVE-2026-78510) *

- Microsoft Office Outlook Remote Code Execution Vulnerability (CVE-2026-78509)

- Microsoft Office Word Remote Code Execution Vulnerability (CVE-2026-78507)

For me, the most notable one is the CVE-2026-78510, the Microsoft Security Update Guide page's title is quite misleading as it didn't even say it affects Outlook. In fact, it's a zero-click RCE (or someone like to call it "half-click") on Microsoft Outlook affecting the Preview Pane, means the bug could be triggered as long as the user previews or opens the email on Outlook. I'm communicating with MSRC to hopefully address the misleading webpage. I recommend patching it sooner rather than later.

Btw, if you're worrying potential Outlook zero-click/half-click 0day attacks, I've put significant efforts in my

) where it should be good at detecting such advanced attacks. It accepts email formats (.msg, .eml) and it checks deeply for various attack vectors!