Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-100208PATCHED
Microsoft · Microsoft 365 Apps for Enterprise

Microsoft Office Outlook Remote Code Execution Vulnerability

Description

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Affected Products

VendorProductVersions
MicrosoftMicrosoft 365 Apps for Enterprise16.0.1, 16.0.1, 16.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftmicrosoft office ltscmitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-100208(vendor-advisory, patch)

Related News (2 articles)

Tier C
VulDB2d ago
CVE-2026-100208 | Microsoft Outlook integer overflow
→ No new info (linked only)
Tier A
Microsoft MSRC2d ago
CVE-2026-100208 Microsoft Office Outlook Remote Code Execution Vulnerability
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://aka.ms/OfficeSecurityReleases
CWECWE-190
PublishedSep 25, 2026
Last enriched2d ago
Trending Score32
Source articles2
Independent2
Info Completeness7/14
Missing: title, description, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85880EXPKEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Trending: 81
HIGHCVE-2026-65660
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 74
HIGHCVE-2026-70125
Microsoft Office Outlook Remote Code Execution Vulnerability
Trending: 33
HIGHCVE-2026-66804
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Trending: 26
CRITICALCVE-2026-70352
Azure AI Language Elevation of Privilege Vulnerability
Trending: 24

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 25, 2026
Discovered by ZDM
Sep 25, 2026
Patch Available
Sep 26, 2026