CVE-2026-70329Disclosure(microsoft / 365_apps)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft 365_apps systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office_2019
  • office_2021
  • office_2024

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 7 mentions (2026-08-12); latest day: 1
  • 11 total mentions across 5 days

Affected systems

Vendors
Products
365_appsoffice_2019office_2021office_2024outlook

2 versions affected across 5 products

Deep dive

Activity timeline11 mentions / 5d
02457Mentions · 2026-08-11: 1Mentions · 2026-08-12: 7Mentions · 2026-08-13: 1Mentions · 2026-08-19: 1Mentions · 2026-08-27: 1Patch / Workaround · 2026-08-12: 4Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 6Technical Details · 2026-08-13: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-27: 108-1108-1208-1308-1908-27
Signal classification3 categories
Disclosure
660.0%
Patch
330.0%
General
110.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-111
Disclosure1
2026-08-127
Disclosure3General1Patch2
2026-08-131
Disclosure1
2026-08-191
Disclosure1
2026-08-271
Patch1
Full discourse11 posts
  • Cyber Security News@The_Cyber_News
    Disclosure

    Microsoft Outlook RCE 🚨 just dropped — CVE-2026-70329 lets attackers hijack your PC with a single malicious email attachment. Patch NOW. 🧵👇 Vulnerability Details: https://cybersecuritynews.com/microsoft-outlook-rce-vulnerability-2/ #cybersecuritynews https://t.co/2vzeQh6s9o

    Post summary

    A new Outlook RCE (CVE-2026-70329) has been announced, warning users to apply a patch immediately to prevent exploitation via malicious email attachments.

    2101732015763.2K
    73.7K followersView on X
  • Dr. Mazin Al-Busaidi@mazin_dr38737
    Disclosure

    🚨 تحذير أمني: ثغرة خطيرة في Microsoft Outlook برقم CVE-2026-70329 وتقييم 8.8 (RCE)! تسمح للمخترق بتنفيذ أوامر عن بُعد، سرقة ملفاتك، أو زرع برمجيات خبيثة. الاستغلال يتطلب تفاعل المستخدم مثل فتح أو معاينة الإيميل الخبيث. 💡 نصيحة تقنية: راقبوا أي نشاط مريب لعمليات مثل powershell.exe أو cmd.exe تنطلق من تطبيق Outlook. حتى الآن لا يوجد استغلال نشط معروف، لكن الوقاية أهم خطوة. إذا كنت تستخدم Outlook في عملك، حدّث فوراً ولا تؤجل التحديثات الأمنية الرسمية لحماية بياناتك. #CyberSecurity #Microsoft #Outlook #CVE #RCE #تقنية #أمن_المعلومات

    Post summary

    The post announces CVE-2026-70329, an RCE flaw in Microsoft Outlook, provides technical details, and urges users to apply official patches, noting no evidence of active exploitation.

    09080214
    1.2K followersView on X
  • ThreatLoom@ThreatLoom

    Worth noting the user-interaction requirement here. CVE-2026-70329 is an 8.8 RCE, but exploitation requires the victim to open a crafted malicious file. Microsoft currently rates exploitation as unlikely, with no evidence of active exploitation. Still one to patch — just an important distinction for risk prioritization.

    200901.3K
    8 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 Microsoft Outlook'ta, özel hazırlanmış bir Office dosyasının açılmasıyla tetiklenebilen ve saldırganın uzaktan kod çalıştırmasına olanak sağlayabilecek CVSS 8.8 skorlu bir integer overflow açığı (CVE-2026-70329) duyuruldu ve patchlendi. Açığın aktif olarak istismar edildiğine dair bir kanıt bulunmuyor. Outlook/Office güncellemelerini mutlaka yükleyin.

    Post summary

    A CVE‑2026‑70329 integer‑overflow flaw in Microsoft Outlook (CVSS 8.8) was disclosed and patched; there is no evidence of active exploitation, and users are advised to install the available updates.

    00011288
    1.6K followersView on X
  • EFANI Secure Cellphone Service@efani
    Patch

    🚨 A high-severity Microsoft Outlook RCE just dropped. CVE-2026-70329 can let attackers run malicious code on your PC after you open a weaponized Office attachment. Patch now. Microsoft has patched a high-severity Outlook vulnerability that could let an attacker run malicious code after a user opens a weaponized Office file. No active exploitation has been reported. But enterprises should not mistake “user interaction required” for low risk. Email attachments remain one of the easiest routes into a corporate endpoint. For Microsoft 365 users, one compromised workstation can become a foothold into the wider work environment: cached credentials, active sessions, synced OneDrive files, Teams conversations, SharePoint data, and any internal systems available to that employee. The vulnerability does not automatically compromise those services. The danger is that Microsoft’s tightly connected ecosystem can magnify the damage from one successful click. Organizations should confirm that August’s security update reached every managed, remote, and rarely connected device. Pay particular attention to legacy or manually serviced Outlook 2016 deployments, restrict risky Office attachments, and investigate unusual processes launched by Outlook. Users should update Office now and avoid unexpected Office files, even when they appear to come from a familiar contact. “Exploitation unlikely” describes the situation today. It is not a reason to leave a widely deployed email client exposed.

    Post summary

    Microsoft released a patch for high‑severity CVE‑2026‑70329, an RCE in Outlook triggered by malicious attachments; no active exploitation documented, but users are urged to update immediately.

    00010440
    9.2K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSec Daily ✓ · 📧 Microsoft Security · 12 August 2026 🎯 New Microsoft Outlook flaw could allow remote code execution Microsoft's August security release includes CVE-2026-70329, a high-severity vulnerability affecting Outlook. The flaw stems from an integer overflow/wraparound condition and carries a CVSS score of 8.8. Microsoft assesses that an attacker could potentially execute arbitrary code over a network, although there was no evidence of active exploitation when the vulnerability was disclosed. 🔗 Source: Microsoft MSRC / Cyber Security News #Outlook #Microsoft #RCE #Vulnerability #CyberSecurity

    Post summary

    The article announces CVE-2026-70329, detailing an integer overflow flaw in Outlook with high CVSS, noting no evidence of active exploitation or available fixes.

    0001075
    42 followersView on X
  • Windows Forum@windowsforum
    Patch

    🚨 Outlook’s CVE-2026-70329 scores 8.8: no login needed, just a malicious Office file and one click. Patch it—because “don’t open that attachment” isn’t a security strategy. https://windowsforum.com/security-alerts.84/cve-2026-70329-microsoft-outlook-remote-code-execution-vulnerability.443685/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MicrosoftSecurity #Msrc #Cve202670329 https://t.co/WVp1AYArtu

    Post summary

    The post highlights the Outlook CVE‑2026‑70329, explains the flaw involves a malicious Office file that allows remote code execution with no login, and urges users to apply the vendor patch.

    0000087
    1.3K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft Outlook の脆弱性 CVE-2026-70329:強力なフィッシング手段となる恐れ https://iototsecnews.jp/2026/08/12/microsoft-outlook-vulnerability-allows-attackers-to-execute-malicious-code-remotely/ メール処理ソフトウェアである Microsoft Outlook において、数値の算術処理の誤りに由来するメモリ破損とリモートコード実行の脆弱性 CVE-2026-70329 が公開されました。悪意あるファイルを開かせるフィッシング攻撃を介して、端末の権限を奪われる恐れがあります。影響を低減するための手順として、最新の修正パッチの適用/受信メールの添付ファイル検知ルールの見直し/組織内における不審なメッセージへの警戒徹底が重要となります。環境に応じた手動による更新などの、早期の対応が推奨されます。 #CVE202670329 #Microsoft #Outlook #Vulnerability

    Post summary

    Microsoft Outlook CVE-2026-70329 is a disclosed vulnerability causing memory corruption and remote code execution via malicious attachment; applying the latest patch and tightening email filtering is advised.

    00000200
    507 followersView on X
  • TECHEPAGES@techepages
    Disclosure

    Microsoft has disclosed CVE-2026-70329, a high-severity (CVSS 8.8) Outlook remote code execution flaw. Attackers could exploit integer overflow via malicious Office files, e nabling arbitrary code execution with no prior privileges. While exploitation is currently deemed unlikely, organizations are urged to apply August 2026 security updates promptly and monitor suspicious email attachments.

    Post summary

    Microsoft disclosed CVE‑2026‑70329, detailing an integer‑overflow RCE in Outlook with a high CVSS score and prompting users to patch with the August 2026 update; no PoC, exploit code, or active exploitation was reported.

    0000050
    38 followersView on X
  • CSIRT TELCONET@CSIRT_Telconet
    General

    Vulnerabilidad de ejecución remota de código en Microsoft Outlook (CVE-2026-70329) Más información: https://csirt.telconet.net/comunicacion/boletines-servicios/vulnerabilidad-de-ejecucion-remota-de-codigo-en-microsoft-outlook-cve-2026-70329/ https://t.co/eMGBPJkN8c

    Post summary

    The post announces CVE‑2026‑70329 as a remote code execution flaw in Microsoft Outlook and directs readers to a CSIRT link for further details.

    00000115
    864 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-70329 Microsoft Office Outlook Integer Overflow Enables Network Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-70329

    Post summary

    The tweet announces CVE-2026-70329, noting an integer overflow in Microsoft Office Outlook that can lead to network‑based code execution.

    00000120
    4.1K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftoffice_2019--x64
Appmicrosoftoffice_2019--x86
Appmicrosoftoffice_2021--x64
Appmicrosoftoffice_2021--x86
Appmicrosoftoffice_2024--x64
Appmicrosoftoffice_2024--x86
Appmicrosoftoutlook2016-x64
Appmicrosoftoutlook2016-x86

Explore more