Skip to content

Release roundup

Microsoft vulnerabilities week 39 of 2026: two Outlook remote code execution flaws fixed

High 8.8 Vendor: Microsoft 2 CVEs in scope Published

Microsoft's week 39 release covers two high-severity Microsoft Office Outlook remote code execution vulnerabilities affecting Microsoft 365 Apps for Enterprise, Office LTSC 2021 and Office LTSC 2024. Neither is in CISA KEV or known to be exploited. Apply the Office security fixes.

The release at a glance

Microsoft's week 39 release, covering 21 September to 27 September 2026, contains two CVEs and both are rated high severity. They are CVE-2026-70125 and CVE-2026-100208, each described as a Microsoft Office Outlook remote code execution vulnerability. The release summary records one CVE under Microsoft Office and one under Microsoft 365 Apps for Enterprise. The affected products listed in the CVE records are Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024. Microsoft rates CVE-2026-70125 as Important; no Microsoft severity rating is stated for CVE-2026-100208. Neither CVE appears in CISA KEV and neither is recorded as currently exploited. The CVE records also do not show public disclosure for either issue. Fixes are available for both.

What matters most

In this release, both CVE records list the same affected Office installations: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024. Both are Outlook remote code execution flaws. For both, an attacker would need to convince a user to interact with malicious content over the network, and no privileges are listed as required, though user interaction is required. The SSVC fields list exploitation as none and automatable as no for both CVEs.

CVE-2026-70125 is the higher-scoring issue. Its CVSS 3.1 score is 8.8 (high), with a network attack vector, low attack complexity, no privileges required and user interaction required. The published vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C, showing high impact on confidentiality, integrity and availability. Microsoft rates the vulnerability Important. The CVE record lists an EPSS percentage of 0.4.

CVE-2026-100208 is also a remote code execution issue in Outlook, described in the CVE record as an integer overflow or wraparound, CWE-190. Its CVSS 3.1 score is 7.5 (high), with a network attack vector, high attack complexity, no privileges required and user interaction required. The published vector also shows high impact on confidentiality, integrity and availability. Microsoft's severity rating is not stated for this CVE. The CVE record lists an EPSS percentage of 0.3.

Patch in this order

  1. Patch CVE-2026-70125 first across Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024. It has the higher score (8.8), a network attack vector, low attack complexity and no privileges required. The fix is available through Microsoft's Office Security Releases guidance.
  1. Patch CVE-2026-100208 next. It is also a network-origin, no-privilege Outlook remote code execution issue, with a 7.5 CVSS score and high attack complexity. The same affected product set applies and the same Office Security Releases fix is available.
  1. Neither CVE is in CISA KEV, so no CISA remediation due date applies. Workarounds are not stated for either CVE, making patching the primary control. Confirm that Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024 are all covered by the update.

Beyond the patch

Microsoft Office releases like this one become more manageable when you can see which Office installations are exposed and when detection can follow the code-execution activity that a successful lure would leave. Virtual CISO Services (vCISO) supports exposure management for network-reachable, no-credential attack surface, and Managed Detection & Response (MDR) monitors for the process and command activity left behind by remote code execution attempts. That turns a two-CVE Office update into a known patch-and-detect cycle rather than a monthly scramble.

Every CVE in this release

CVEProductSeverity
CVE-2026-70125Microsoft 365 Apps for EnterpriseHigh 8.8
CVE-2026-100208Microsoft 365 Apps for EnterpriseHigh 7.5

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.