CVE-2026-40361Patch(microsoft / 365_apps)

HIGHCVSS 8.4 · HIGH

Exploitation observed; activity peaked at 20 mentions and remains active

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

6.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office
  • office_long_term_servicing_channel
  • word

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 42 mentions across 8 observed days

What's happening

  • Active exploitation reported across 5 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 29 signals
  • Technical details provided in 33 signals
  • Disclosure: 9 classified signals
  • Peaked 6d ago at 20 mentions (2026-05-13); latest day: 1
  • 42 total mentions across 8 days

Affected systems

Vendors
Products
365_appsofficeoffice_long_term_servicing_channelword

5 versions affected across 4 products

Deep dive

Activity timeline42 mentions / 8d
05101520Mentions · 2026-05-12: 5Mentions · 2026-05-13: 20Mentions · 2026-05-14: 8Mentions · 2026-05-15: 3Mentions · 2026-05-16: 2Mentions · 2026-05-19: 2Mentions · 2026-05-23: 1Mentions · 2026-06-03: 1PoC Mentioned / Linked · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-15: 1Active Exploitation · 2026-05-13: 5Patch / Workaround · 2026-05-12: 3Patch / Workaround · 2026-05-13: 15Patch / Workaround · 2026-05-14: 4Patch / Workaround · 2026-05-15: 3Patch / Workaround · 2026-05-16: 2Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-05-12: 4Technical Details · 2026-05-13: 16Technical Details · 2026-05-14: 7Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 2Technical Details · 2026-05-19: 2Technical Details · 2026-06-03: 105-1205-1305-1405-1505-1605-1905-2306-03
Signal classification4 categories
Patch
2559.5%
Disclosure
921.4%
Active Exploitation
511.9%
General
37.1%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-125
Disclosure2Patch3
2026-05-1320
Active Exploitation5Disclosure3General1Patch11
2026-05-148
Disclosure3General1Patch4
2026-05-153
Patch3
2026-05-162
Patch2
2026-05-192
Disclosure1Patch1
2026-05-231
General1
2026-06-031
Patch1
Full discourse20 posts
  • Haifei Li@HaifeiLi
    Patch

    CVE-2026-40361 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40361), patched today, is a critical 0-click UAF/RCE bug in Microsoft Outlook that I discovered back in Q1. You definitely want to patch this sooner rather than later. The danger of such 0-click bugs in Outlook is that they are triggered as soon as the victim reads or previews the email - no clicking of links or attachments is required. Since the bugs reside in Outlook's email rendering engine, it is difficult to mitigate or block (though specifically setting Outlook to render emails only in plain text format is a valid mitigation). Fun fact about the discovery: after the discovery of the #BadWinmail bug a decade ago, I wanted to run an experiment in Q1 to see if I could find another 0-click RCE in Outlook. The result? It wasn't easy — I even built a dedicated system for it — but I eventually found this one. :) To understand why such bugs are so critical, check out the #BadWinmail video demo I released a decade ago: https://www.youtube.com/watch?v=ngWVbcLDPm8. They share the same attack vector (though #BadWinmail was a working exploit, while this one was a PoC). Essentially, anyone could compromise a CEO or CFO just by sending an email. The threat perfectly bypasses enterprise firewalls and is delivered directly to the inbox. Furthermore, note that Outlook (Classic) lacks an application sandbox, making this attack vector even more dangerous. Regarding defense and detection: if you are concerned about Outlook 0-click 0-days, my EXPMON system (https://pub.expmon.com) provides cutting-edge detection against such advanced threats. When I designed the original system in 2020/2021, I developed this functionality specifically considering the impact of #BadWinmail. The system accepts .eml or .msg formats, and email samples are deeply tested within an Outlook sandbox. For enterprise users, emails can be "dumped" from the mail server, and EXPMON can be deployed in a private network. Contact me for more details. P.S. I just noted that the title of the Microsoft Security Update (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40361) lists this as a Microsoft Word bug, which may or may not be entirely accurate. I demonstrated this bug to MSRC by showing that it works in a real, live Outlook + Exchange Server environment. My bet is that because the bug resides in wwlib.dll — a shared DLL used heavily by both Outlook and Word — it likely affects both Outlook (via email) and Word (via a document file). Regardless of the title, it is a genuine Outlook 0-click RCE. #CVE-2026-40361 #PatchTuesday #Outlook #0click #EmailSecurity #EnterpriseSecurity #expmon #ThreatIntel #ExploitDetection

    Post summary

    The post announces that CVE‑2026-40361, a 0‑click UAF/RCE flaw in Outlook, has been patched today and urges immediate application, while also noting the vulnerability’s severity and recommended mitigation. No evidence of active exploitation or false‑positive status is provided.

    6851142519269.1K
    8.9K followersView on X
  • Haifei Li@HaifeiLi
    Patch

    After communicating with @msftsecresponse (the process took a bit longer because my emails somehow got lost along the way..), they have now updated the official Security Update Guide for CVE-2026-40361 (background: https://x.com/HaifeiLi/status/2054268761528823931). Hopefully, this will clear up some confusions and help users prioritize their patching strategies. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40361 The advisory now explicitly states that this bug affects both Outlook and Word, and that the Outlook Preview Pane is an affected vector — meaning it is indeed a 0-click attack vector, triggered as soon as the victim reads or previews the email. I still have a bit of question — for instance, why the Attack Vector in the CVSS score is still classified as "Local" — but then again, I'm no CVSS expert. Anyway, as long as people recognize that this is a dangerous, email-based Outlook 0-click RCE, I’m happy. :)

    Post summary

    The post announces Microsoft’s updated security advisory for CVE‑2026‑40361, clarifies that the 0‑click RCE affects Outlook and Word via the preview pane, and urges users to apply the official patch.

    17041179.1K
    8.9K followersView on X
  • Haifei Li@HaifeiLi
    Disclosure

    Yea, weird one.. If I didn't post about it, looking at Microsoft's Security Update page https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40361, nobody knows it's an Outlook 0-click RCE.. https://x.com/sekurlsa_pw/status/2054272782767132924

    Post summary

    The user highlights that CVE‑2026‑40361, documented on Microsoft’s Security Update page, is an Outlook 0‑click remote code execution vulnerability. No PoC, exploit code, or patch details are provided in the post.

    211135106.8K
    8.9K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    💥 Outlook - Faille zéro clic Le Patch Tuesday de mai 2026 publié par Microsoft corrige une faille de type zero-click affectant Outlook (et Word) : CVE-2026-40361. Voici comment se protéger. - https://www.it-connect.fr/outlook-cve-2026-40361-cette-faille-zero-click-menace-les-entreprises-patchez/ #outlook #infosec #microsoft https://t.co/zxxc5y2324

    Post summary

    Microsoft released a Patch Tuesday update in May 2026 that fixes the zero-click CVE-2026-40361 affecting Outlook and Word, and the tweet provides guidance on how to protect against it.

    01002242.0K
    11.5K followersView on X
  • innovaTopia@innovaTopia_JP
    Disclosure

    Outlook ゼロクリック脆弱性 CVE-2026-40361|メール閲覧だけで企業が侵害されるリスク https://innovatopia.jp/cyber-security/cyber-security-news/102741/ 【ゼロクリック脆弱性】 ユーザーが何も操作しなくても発動する脆弱性。添付ファイルのクリックもリンクの踏み込みも不要で、メールの受信・プレビュー表示だけで成立する

    Post summary

    This piece informs about a zero‑click vulnerability in Outlook (CVE‑2026‑40361) that can be activated by simply opening an email, emphasizing the risk without providing evidence of active exploitation, a PoC, or mitigation.

    02030218
    472 followersView on X
  • Tre B@trerbbb
    Patch

    microsoft CVE-2026-40361: RCE. patch tuesday came early. assume mass scanning starts within 48h. #Microsoft #RCE #AIsecurity #CVE-2026-40361 https://valtikstudios.com/blog

    Post summary

    The tweet announces Microsoft CVE‑2026‑40361 (an RCE) has been patched early, suggesting that mass scanning may start soon.

    02020132
    15 followersView on X
  • SI-CERT@sicert
    Patch

    Prejšnji teden je Microsoft izdal popravke za 137 ranljivosti. Izpostavljamo ranljivost CVE-2026-40361, ki po podatkih odkritelja obstaja tudi v Outlooku, pri čemer se lahko sproži že ob predogledu ali če žrtev zgolj odpre posebej prirejen email. #patch https://www.securityweek.com/microsoft-patches-critical-zero-click-outlook-vulnerability-threatening-enterprises/

    Post summary

    Microsoft has issued patches for CVE‑2026‑40361, an Outlook zero‑click vulnerability that can be triggered by preview or opening a specially crafted email, and the article focuses on the availability of these fixes.

    01020477
    4.4K followersView on X
  • Elusive@ElusivePrivacy
    Patch

    1/2 Microsoft patches CVE-2026-40361 zero-click RCE in Outlook via preview pane. Use-after-free in email rendering DLL shared with Word. No user interaction needed. Researcher Haifei Li (Expmon) compares it to BadWinmail (CVE-2015-6172), the "enterprise killer" from 2015.

    Post summary

    Microsoft released a patch for the zero‑click RCE vulnerability CVE-2026-40361 in Outlook, detailing a use‑after‑free flaw in the preview pane DLL shared with Word, with no active exploitation or PoC reported.

    11010114
    172 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - Microsoft Office Word Use-After-Free (CVE-2026-40361) A critical Use-After-Free (UAF) vulnerability in Microsoft Office Word allows an attacker to achieve local code execution. The flaw exists in how Word handles specific memory objects during document parsing; by re-using a memory pointer after it has been freed, an attacker can corrupt the heap to execute arbitrary commands with the privileges of the current user. 👉 Affected: Microsoft Office 2019, 2021, and Microsoft 365 Apps | Upgrade to May 12, 2026 versions

    Post summary

    A disclosure of a critical UAF vulnerability in Microsoft Office Word (CVE‑2026‑40361) that allows local code execution, with a recommendation to upgrade to the May 12 2026 patch to mitigate the risk.

    00030182
    255 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Patch

    📰 Newsletter RadioCSIRT, N°54 Au sommaire de la semaine du 9 au 15 mai 2026 : famille Dirty Frag (CVE-2026-43284 / 43500), YellowKey contre BitLocker, CVE-2026-40361 zero-click Outlook, AMD-SB-7052, Shai-Hulud, et bien plus. https://open.substack.com/pub/radiocsirt/p/radiocsirt-newsletter-cybersecurite ⚡ On ne réfléchit pas, on patch ! #CyberSecurity #CERT #CTI #DirtyFrag #YellowKey #PatchTuesday

    Post summary

    The newsletter highlights several CVEs and emphasizes that patching is the immediate response, with no mention of proof‑of‑concepts, exploit tools, or active attacks.

    01010139
    422 followersView on X
  • Cyber News Live@cybernewslive
    Patch

    Microsoft has patched a critical security flaw in Outlook — tracked as CVE-2026-40361 — that can be triggered simply by reading or previewing an email, with no clicking required. The flaw sits in the rendering engine shared by Word and Outlook, making it difficult to block at the network level. The researcher who found it compared it to a 2015 flaw he called an 'enterprise killer', saying it could let anyone compromise a senior executive just by sending them an email. Open Outlook, go to File → Options → Trust Center → Trust Center Settings → Email Security, and enable 'Read all standard mail in plain text' — this disables the rendering engine the attack relies on, until your IT team confirms the patch is applied. 🔥 #CyberNewsLive https://securityweek.com/microsoft-patches-critical-zero-click-outlook-vulnerability-threatening-enterprises/

    Post summary

    Microsoft has patched CVE‑2026‑40361, a zero‑click Outlook vulnerability; a temporary workaround of disabling rich rendering is advised until the official patch is applied. No active exploitation or PoC is reported.

    10010190
    2.0K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises - SecurityWeek https://www.securityweek.com/microsoft-patches-critical-zero-click-outlook-vulnerability-threatening-enterprises/ "The Outlook vulnerability is tracked as CVE-2026-40361 and it has been described by Microsoft as a remote code execution vulnerability affecting Word."

    Post summary

    Microsoft has issued a patch for CVE-2026-40361, a critical remote code execution flaw in Outlook affecting Word, with no evidence of PoC, exploit, or active exploitation reported.

    00011233
    3.5K followersView on X
  • TheFactumAI@TheFactumAI
    Disclosure

    @IntCyberDigest CVE-2026-40361 enables zero-click RCE in Outlook solely via email preview rendering, no interaction required. Parallels the DNS flaw in exposing enterprises to rapid state-sponsored exploitation amid slow patching and cloud dependency.

    Post summary

    The tweet announces CVE-2026-40361 as a zero‑click RCE in Outlook triggered by email preview rendering, noting potential rapid state‑sponsored exploitation but lacking evidence of active use or available patches.

    00002293
    19 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Microsoft patched CVE-2026-40361, a critical zero-click Outlook bug that can trigger code execution from just reading or previewing an email. The flaw raises serious risks for enterprise inboxes. #Outlook #ExchangeServer #BadWinmail https://ift.tt/rBzDJm4

    Post summary

    Microsoft patched CVE-2026-40361, a critical zero-click Outlook flaw that allows code execution by previewing an email, and the post highlights the availability of the fix.

    01010357
    4.3K followersView on X
  • ET Labs@ET_Labs
    Disclosure

    9 new OPEN, 16 new PRO (9 + 7) DOILoader, Outlook Classic Use After Free Remote Code Execution Attempt (CVE-2026-40361), Rclone (CVE-2026-41176, CVE-2026-41179), TA569, Win32/Lumma Stealer https://community.emergingthreats.net/t/ruleset-update-summary-2026-05-12-v11191/3315

    Post summary

    The bulletin announces several newly discovered CVEs with technical details, but lacks evidence of active exploitation, patches, or PoC availability.

    01010305
    5.7K followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Patch

    CVE-2026-40361 : UN E-MAIL SUFFIT. Pas de clic. Pas de pièce jointe ouverte. Pas de macro activée. Le simple affichage du message dans le volet de lecture Outlook suffit à déclencher l'exécution de code via une corruption mémoire dans wwlib.dll, la DLL partagée par Word et Outlook. Microsoft a publié le correctif le 12 mai 2026 dans le Patch Tuesday mensuel. CVSS 8.4. Exploitation More Likely. Découverte revendiquée par Haifei Li, le chercheur déjà à l'origine de BadWinmail il y a dix ans, qui qualifie cette nouvelle vulnérabilité de successeur direct de son « enterprise killer » de 2015. Le profil d'attaque est défavorable au défenseur sur quatre dimensions : déclenchement zero-click via volet de lecture, livraison directe en boîte de réception, absence de bac à sable applicatif dans Outlook Classic, partage du code path avec Word et l'Explorateur Windows. Dans l'article, je détaille la chaîne technique, les conditions d'exploitation, les mitigations applicables immédiatement (patch, rendu texte brut, désactivation du volet de lecture, règles ASR Defender), les indicateurs comportementaux pertinents pour les équipes EDR, et la comparaison avec les RCE Word historiques (Equation Editor, Follina, EPM NTLM relay). À lire et à diffuser aux populations à risque élevé : direction, finance, RH, achats, juridique, communication externe. 🧑‍💻https://blog.marcfredericgomez.fr/cve-2026-40361-vulnerabilite-zero-click-use-after-free-dans-le-moteur-de-rendu-outlook-wwlib-dll/ On ne réfléchit pas, on patch ! #CyberSecurity #CTI #VulnerabilityManagement #PatchTuesday #Microsoft #Outlook #ZeroClick #CVE202640361 #ThreatIntelligence #CERT #VOC #IncidentResponse #RadioCSIRT

    Post summary

    The post announces CVE‑2026‑40361, a zero‑click memory corruption in Outlook/Word via wwlib.dll, notes Microsoft’s patch issued on 12 May 2026, and provides technical exploitation details along with immediate mitigations.

    01000112
    422 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    Microsoft Wordの脆弱性 CVE-2026-40361に注意、Outlookでゼロクリック型サイバー攻撃への悪用の恐れ https://rocket-boys.co.jp/security-measures-lab/microsoft-word-zero-click-outlook-cve-2026-40361/ #セキュリティ対策Lab #security #securitynews #cyberattack

    Post summary

    The post alerts users to the presence of CVE-2026-40361 in Microsoft Word and warns of potential zero-click exploitation via Outlook, but provides no detailed technical info, PoC, exploit tool, patch note, or evidence of active attacks.

    00010205
    405 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Recent zero-day RCEs in Microsoft Outlook (CVE-2026-40361) and Canon GUARDIANWALL, plus critical NGINX & Exim flaws, threaten data privacy & integrity in transit. Patch immediately! #Cybersecurity #ZeroDay #News

    Post summary

    The post reports zero‑day RCEs in Microsoft Outlook (CVE‑2026‑40361) and Canon GuardianWall, plus critical NGINX and Exim flaws, and urges immediate patching to protect data privacy and integrity.

    10000185
    14 followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【Microsoft CVE-2026-40361、OutlookゼロクリックRCEとして優先パッチ対象】 Microsoftの2026年5月月例更新で修正されたCVE-2026-40361は、Outlook/Word関連のCritical RCEとして特に注意が必要です。研究者は、Outlookでメールを読む、またはプレビューするだけで発火し得るゼロクリックuse-after-freeと説明しています。 この種の脆弱性は、リンククリックや添付ファイル実行を必要としません。攻撃メールが受信箱に届き、Outlookの描画エンジンが処理するだけで初期アクセスに至る可能性があります。 防御側は、Office/Outlook更新を最優先で適用し、暫定的にプレーンテキスト表示や外部コンテンツ制御を検討してください。EDRでは、`OUTLOOK.EXE`や`WINWORD.EXE`からのPowerShell/cmd/mshta起動、異常クラッシュ、未知通信を重点的に確認します。 #Microsoft #Outlook #CVE202640361 #ZeroClick #RCE #PatchTuesday #SOC https://www.securityweek.com/microsoft-patches-critical-zero-click-outlook-vulnerability-threatening-enterprises/

    Post summary

    Microsoft’s May 2026 update fixed CVE-2026-40361, a zero‑click use‑after‑free RCE in Outlook/Word; organizations should prioritize updating Office, enable plain‑text viewing, and control external content to mitigate the critical vulnerability.

    10000510
    3.7K followersView on X
  • ZeroDayDev@ZeroDayDevApp
    Patch

    Microsoft patched CVE-2026-40361, a critical zero-click RCE in Outlook that requires no user interaction to compromise enterprise networks. Similar to BadWinmail from a decade ago, which was called an "enterprise killer" at the time. No click, no attachment, just parsing a malformed email. https://www.securityweek.com/microsoft-patches-critical-zero-click-outlook-vulnerability-threatening-enterprises/

    Post summary

    Microsoft has released a patch for CVE‑2026‑40361, a zero‑click RCE in Outlook that exploits malformed emails without user interaction.

    0001086
    97 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-
Appmicrosoftword2016-x64
Appmicrosoftword2016-x86

Explore more