Junglewise Threat Intelligence

CVE-2026-80073: Microsoft Office Outlook out-of-bounds read information disclosure

CVE-2026-80073 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office Outlook contains an out-of-bounds memory read vulnerability that allows an attacker to access sensitive information over the network. An unauthenticated remote attacker could exploit this flaw to disclose confidential data without user interaction, potentially exposing email contents or other private information stored within Outlook.

Technical details

This vulnerability is an out-of-bounds read in Microsoft Office Outlook's memory handling. The flaw permits an unauthorized, remote attacker to read memory outside the intended bounds of a buffer or data structure, leading to information disclosure. The attack vector is network-based and requires no authentication or user interaction. A successful exploit could allow an attacker to extract sensitive data from the affected system. Microsoft has released security patches through its regular update channels to remediate this issue.

Affected products

  • Microsoft Office Outlook

Timeline

  • 2026-09-08: disclosed

References

Related threats