Vulnerability
Published 2026-09-23
Verified 2026-09-27

Microsoft Outlook RCE CVE-2026-70125 (CVSS 8.8): M365 Apps / Office LTSC 2021 & 2024 — UI:R network vector

NVD/MSRC (published 23 September 2026) lists CVE-2026-70125 as a Microsoft Outlook Remote Code Execution vulnerability. Microsoft CVSS 3.1 base 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Affected product lines named in the NVD record: Microsoft 365 Apps for Enterprise; Microsoft Office LTSC 2021; Microsoft Office LTSC 2024 (version ranges point to Office security releases via aka.ms/OfficeSecurityReleases). No public exploitation claim in the NVD “Received” record reviewed this pass. Apply current Office/Outlook security updates from the MSRC update guide; do not invent build numbers beyond the vendor release channel.

Product
Microsoft Outlook (Microsoft 365 Apps for Enterprise; Office LTSC 2021; Office LTSC 2024)
Versions
See MSRC / aka.ms/OfficeSecurityReleases for the fixed Office security release channel
CVSS
(CVSS 3.1, Microsoft)
Exploited in Australia?
unknown
Patch to
Install current Outlook/Office security updates from MSRC (Office Security Releases channel); prioritise internet-facing and high-risk mail users

Primary: Microsoft MSRC — CVE-2026-70125 Outlook RCE · Vendor: MSRC update guide — CVE-2026-70125 · CVE: CVE-2026-70125 · NVD — CVE-2026-70125 (published 23 Sep 2026)

vulnerabilities australia identity