Junglewise Threat Intelligence

CVE-2026-69629: Microsoft Office Outlook heap-based buffer overflow

CVE-2026-69629 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Outlook is email and calendar software used across organizations to manage communications and schedules. A heap-based buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's computer over the network, potentially leading to data theft, malware installation, or system compromise.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office Outlook's memory handling. The flaw can be exploited by an attacker over a network without requiring user authentication, though successful exploitation may require specific preconditions such as specially crafted email content or attachments. An attacker can leverage this vulnerability to achieve remote code execution (RCE) with the privileges of the affected user. The vulnerability has been assigned CVE-2026-69629 with a CVSS score of 8.8, indicating high severity.

Affected products

  • Microsoft Office Outlook

Timeline

  • 2026-09-08: disclosed

References

Related threats