Microsoft Outlook RCE CVE-2026-70125 (CVSS 8.8): M365 Apps / Office LTSC 2021 & 2024 — UI:R network vector
NVD/MSRC (published 23 September 2026) lists CVE-2026-70125 as a Microsoft Outlook Remote Code Execution vulnerability. Microsoft CVSS 3.1 base 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Affected product lines named in the NVD record: Microsoft 365 Apps for Enterprise; Microsoft Office LTSC 2021; Microsoft Office LTSC 2024 (version ranges point to Office security releases via aka.ms/OfficeSecurityReleases). No public exploitation claim in the NVD “Received” record reviewed this pass. Apply current Office/Outlook security updates from the MSRC update guide; do not invent build numbers beyond the vendor release channel.
- Product
- Microsoft Outlook (Microsoft 365 Apps for Enterprise; Office LTSC 2021; Office LTSC 2024)
- Versions
- See MSRC / aka.ms/OfficeSecurityReleases for the fixed Office security release channel
- CVSS
- (CVSS 3.1, Microsoft)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Install current Outlook/Office security updates from MSRC (Office Security Releases channel); prioritise internet-facing and high-risk mail users
Primary: Microsoft MSRC — CVE-2026-70125 Outlook RCE · Vendor: MSRC update guide — CVE-2026-70125 · CVE: CVE-2026-70125 · NVD — CVE-2026-70125 (published 23 Sep 2026)
