
1/2 Microsoft patches CVE-2026-40361 zero-click RCE in Outlook via preview pane. Use-after-free in email rendering DLL shared with Word. No user interaction needed. Researcher Haifei Li (Expmon) compares it to BadWinmail (CVE-2015-6172), the "enterprise killer" from 2015.
Post summary
Microsoft has issued a patch for CVE‑2026‑40361, a zero‑click RCE in Outlook that exploits a use‑after‑free bug in the preview pane. No evidence of active exploitation or PoC is mentioned.
