Microsoft Outlook Vulnerability CVE-2026-70329 Allows Remote Code Execution
Microsoft has patched CVE-2026-70329, a critical integer overflow vulnerability in Outlook that allows remote code execution via malicious Office files.

Microsoft has released a crucial security update to address CVE-2026-70329, a remote code execution (RCE) vulnerability discovered in its widely-used Outlook email client. This flaw, detailed as part of Microsoft's August 2026 Patch Tuesday, stems from an integer overflow or wraparound weakness within Microsoft Office Outlook. The vulnerability carries a high CVSS v3.1 base score of 8.8, underscoring its critical nature.
An unauthorized attacker could exploit this vulnerability to execute arbitrary code over a network. This capability makes it imperative for organizations running any supported version of Outlook or Office to apply the patch promptly. According to Microsoft's Security Response Center, the vulnerability was not publicly disclosed before its inclusion in the patch release, and there is currently no evidence of active exploitation in the wild. Microsoft's assessment indicates that exploitation is "unlikely" at this time, but this could change rapidly if proof-of-concept exploits become publicly available.
The attack vector for CVE-2026-70329 requires user interaction, meaning it cannot be triggered automatically without the target user performing a specific action. Attackers would typically craft a malicious Office file, often disguised as an email attachment, and then employ social engineering tactics to persuade the recipient to open it. Once the malicious file is opened, the integer overflow vulnerability can be triggered, leading to memory corruption and potentially hijacking program execution.
Successful exploitation could grant the attacker full control over the affected system, with the extent of compromise depending on the victim's privilege level. This exploitation pattern is consistent with many previous memory-corruption vulnerabilities found in Outlook and Office applications, where phishing emails serve as the primary delivery mechanism rather than a fully unauthenticated network-based exploit.
The security update provided by Microsoft addresses a broad range of its Office products. Affected software includes Microsoft 365 Apps for Enterprise (32-bit and 64-bit), Microsoft Office 2019 (both architectures), Microsoft Office LTSC 2021 and LTSC 2024 (32-bit and 64-bit editions), and standalone Microsoft Outlook 2016 (32-bit and 64-bit). For Outlook 2016 specifically, the fix is detailed under Knowledge Base article 5002755, updating the build to version 16.0.5565.1000.
While Click-to-Run editions of Office receive automatic updates through Microsoft's servicing channels, standalone MSI-based installations will require manual deployment of the security update. CVE-2026-70329 was one of 394 vulnerabilities patched by Microsoft in its August 2026 security update cycle, which also included fixes for three actively exploited zero-day vulnerabilities in other product lines.
Microsoft has credited an anonymous researcher for reporting this Outlook RCE vulnerability through its coordinated vulnerability disclosure program. Security teams are strongly advised to prioritize the deployment of the August 2026 cumulative update across all Outlook and Office installations. This is particularly critical for environments still running older versions like Office 2016 or LTSC builds that do not receive automatic updates. In addition to patching, reinforcing user awareness training on phishing and enhancing email attachment filtering can further mitigate risks while patches are being deployed.