CVE-2026-69629
massHeap-Based Buffer Overflow in Microsoft Outlook Enables Remote Code Execution
CVE-2026-69629 is a heap-based buffer overflow (CWE-122) in Microsoft Office Outlook that a remote, unauthenticated attacker can trigger over a network. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates no privileges or credentials are needed on the attacker's side, but the victim must interact with attacker-controlled content — consistent with previewing or opening a specially crafted item in Outlook. A successful exploit lets the attacker execute code in the context of the Outlook user, with high impact on confidentiality, integrity, and availability (CVSS 8.8 High). All users running an affected Outlook build are exposed; effectively that means the very large installed base of Microsoft Office/Outlook users, although the provided data does not enumerate the exact affected versions or products beyond Office Outlook. There is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.8% probability of exploitation in the next 30 days (56th percentile), so no in-the-wild exploitation is currently known.
What to do: Apply Microsoft's security update for Outlook/Office addressing CVE-2026-69629 through Microsoft Update or your Microsoft 365 update channel as soon as it reaches your deployment ring, and verify the affected builds against Microsoft's advisory, since exact versions are not listed in this data. Until patched, reduce exposure by using plain-text reading mode and cautioning users against previewing or opening content from untrusted senders. With no public PoC, no KEV listing, and low EPSS, this can be handled in the normal high-priority patch cycle rather than as an emergency change.
| Microsoft Office Outlook | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- 365 apps, office 2019, office 2021, office 2024, outlook
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.