Microsoft has disclosed a brand new distant code execution flaw in Outlook, tracked as CVE-2026-70329, as a part of its August 2026 Patch Tuesday rollout. The vulnerability stems from an integer overflow or wraparound weak spot in Microsoft Workplace Outlook, and it carries a CVSS v3.1 base rating of 8.8, inserting it within the Excessive severity band.
Microsoft’s advisory notes that an unauthorized attacker may exploit this flaw to execute arbitrary code over a community, making it a precedence patch for organizations working any supported model of Outlook or Workplace.
In line with Microsoft’s Safety Response Heart, the flaw has not been publicly disclosed previous to this launch, and there’s no proof of lively exploitation within the wild.
Microsoft’s exploitability evaluation charges exploitation as “unlikely,” although safety groups are nonetheless urged to patch promptly since exploitability rankings can shift as soon as proof-of-concept code or exploit chains floor publicly.
The assault requires person interplay, that means it can not set off routinely with out the goal taking an motion. An attacker should craft a malicious Workplace file, most certainly disguised as an electronic mail attachment, and persuade the recipient to open it.
Microsoft Outlook RCE Vulnerability
As soon as opened, the integer overflow bug may be triggered to deprave reminiscence and hijack program execution, doubtlessly handing the attacker full management over the affected system relying on the sufferer’s privilege stage.
This sample mirrors many earlier Outlook and Workplace memory-corruption bugs, the place social engineering by phishing emails stays the first supply mechanism reasonably than a completely unauthenticated network-based exploit.
Microsoft’s patch covers a large swath of its Workplace ecosystem. Affected merchandise embody Microsoft 365 Apps for Enterprise on each 32-bit and 64-bit programs, Microsoft Workplace 2019 in each architectures, Microsoft Workplace LTSC 2021 and LTSC 2024 for 32-bit and 64-bit editions, and standalone Microsoft Outlook 2016 releases for each 32-bit and 64-bit programs.
For Outlook 2016, Microsoft has revealed the repair underneath Data Base article 5002755, bringing builds as much as model 16.0.5565.1000. Click on-to-Run editions are up to date routinely by Microsoft’s servicing channel, whereas standalone MSI-based installations require guide deployment of the safety replace.
CVE-2026-70329 was considered one of 394 vulnerabilities Microsoft addressed in its August 2026 security update cycle, which additionally fastened three actively exploited zero-days throughout different product strains.
The Outlook flaw sits alongside a separate Outlook spoofing vulnerability, CVE-2026-62882, rated decrease at 4.3 on the CVSS scale, and several other information-disclosure bugs affecting Excel, Phrase, and PowerPoint. Microsoft has credited an nameless researcher for reporting the Outlook RCE flaw by its coordinated vulnerability disclosure program.
Safety groups ought to prioritize deploying the August 2026 cumulative replace throughout all Outlook and Workplace installations, significantly in environments nonetheless working Workplace 2016 or LTSC builds that don’t obtain automated Click on-to-Run updates.
On condition that exploitation hinges on tricking a person into opening a malicious file, reinforcing phishing consciousness coaching and electronic mail attachment filtering will additional scale back danger whereas patches are rolled out fleet-wide.
[Live Webinar] Be part of Elastic & UnderDefense to find out how small safety groups can unify AI visibility and agentic response into one working mannequin -> Register Now