Microsoft has disclosed a new remote code execution flaw in Outlook, tracked as CVE-2026-70329, as part of its August 2026 Patch Tuesday rollout. The vulnerability stems from an integer overflow or wraparound weakness in Microsoft Office Outlook, and it carries a CVSS v3.1 base score of 8.8, placing it in the High severity band.
Microsoft’s advisory notes that an unauthorized attacker could exploit this flaw to execute arbitrary code over a network, making it a priority patch for organizations running any supported version of Outlook or Office.
According to Microsoft’s Security Response Center, the flaw has not been publicly disclosed prior to this release, and there is no evidence of active exploitation in the wild.
Microsoft’s exploitability assessment rates exploitation as “unlikely,” though security teams are still urged to patch promptly since exploitability ratings can shift once proof-of-concept code or exploit chains surface publicly.
The attack requires user interaction, meaning it cannot trigger automatically without the target taking an action. An attacker must craft a malicious Office file, most likely disguised as an email attachment, and convince the recipient to open it.
Microsoft Outlook RCE Vulnerability
Once opened, the integer overflow bug can be triggered to corrupt memory and hijack program execution, potentially handing the attacker full control over the affected system depending on the victim’s privilege level.
This pattern mirrors many previous Outlook and Office memory-corruption bugs, where social engineering through phishing emails remains the primary delivery mechanism rather than a fully unauthenticated network-based exploit.
Microsoft’s patch covers a wide swath of its Office ecosystem. Affected products include Microsoft 365 Apps for Enterprise on both 32-bit and 64-bit systems, Microsoft Office 2019 in both architectures, Microsoft Office LTSC 2021 and LTSC 2024 for 32-bit and 64-bit editions, and standalone Microsoft Outlook 2016 releases for both 32-bit and 64-bit systems.
For Outlook 2016, Microsoft has published the fix under Knowledge Base article 5002755, bringing builds up to version 16.0.5565.1000. Click-to-Run editions are updated automatically through Microsoft’s servicing channel, while standalone MSI-based installations require manual deployment of the security update.
CVE-2026-70329 was one of 394 vulnerabilities Microsoft addressed in its August 2026 security update cycle, which also fixed three actively exploited zero-days across other product lines.
The Outlook flaw sits alongside a separate Outlook spoofing vulnerability, CVE-2026-62882, rated lower at 4.3 on the CVSS scale, and several information-disclosure bugs affecting Excel, Word, and PowerPoint. Microsoft has credited an anonymous researcher for reporting the Outlook RCE flaw through its coordinated vulnerability disclosure program.
Security teams should prioritize deploying the August 2026 cumulative update across all Outlook and Office installations, particularly in environments still running Office 2016 or LTSC builds that don’t receive automatic Click-to-Run updates.
Given that exploitation hinges on tricking a user into opening a malicious file, reinforcing phishing awareness training and email attachment filtering will further reduce risk while patches are rolled out fleet-wide.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now

