CVE-2026-100208

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-25: 209-25
Referenced assets1 URL
Full discourse2 posts
  • Xavier Rivera@XavierRiveraX

    Outlook CVE-2026-100208: integer overflow that can become network RCE. Microsoft scores it 7.5 High. Needs a user click, high complexity, no privileges. NVD has no patch or version list yet. Until Microsoft maps builds, treat surprise calendar invites and attachment opens as high-risk. Same for GCC and commercial tenants.

    01010124
    601 followersView on X
  • The Circuitry@thecircuitry_

    Microsoft Outlook flaw CVE-2026-100208 could allow remote code execution. • Integer overflow, CVSS 7.5 (High) per Microsoft • Needs user interaction, no privileges • Attack complexity rated high https://thecircuitry.to/article/microsoft-outlook-flaw-cve-2026-100208-could-allow-remote-code-execution-muheu7lm

    0000041
    37 followersView on X

Explore more