CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond

Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office file. Review the exact affected editions, deploy the August 11 security release, and verify the installed build by servicing channel.

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseBriefing · 5 min read
Executive summary

What you need to know

Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office file. Review the exact affected editions, deploy the August 11 security release, and verify the installed build by servicing channel.

Potentially affected

Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021, Office LTSC 2024, and Outlook 2016 on Windows, in the 32-bit and 64-bit editions listed by Microsoft.

DSE recommendation

Inventory Office product, architecture, channel, and build; deploy the August 11, 2026 security update or later; install KB5002755 on MSI-based Outlook 2016; and verify the resulting build on every managed endpoint.

The bottom line

Microsoft released security updates on August 11, 2026 for CVE-2026-70329, a remote code execution vulnerability in Microsoft Office Outlook caused by an integer overflow or wraparound. Microsoft rates the issue Important and assigns it a CVSS v3.1 base score of 8.8 (High).

This is not a zero-click vulnerability based on the information Microsoft has published. An attacker must send a malicious Office file and convince the recipient to open it. That required interaction lowers the likelihood of automatic exploitation, but the potential consequences remain serious: the published CVSS assessment assigns high confidentiality, integrity, and availability impact.

DSE recommendation: identify affected Windows Office installations, deploy the appropriate August 11 Office security release or later, and verify the resulting build on each managed update channel. Do not treat email filtering or user awareness as a replacement for the security update.

What Microsoft has confirmed

  • Vulnerability: CVE-2026-70329, Microsoft Outlook Remote Code Execution Vulnerability.
  • Weakness: CWE-190, Integer Overflow or Wraparound.
  • Severity: Important under Microsoft’s rating system; CVSS v3.1 8.8 (High).
  • Published vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
  • Required user action: the recipient must open a malicious Office file supplied by the attacker.
  • Customer action: required. Microsoft has released fixes and does not list a separate workaround.

The CVSS vector indicates no attacker privileges are required, attack complexity is low, and user interaction is required. Microsoft has not publicly identified the exact file format or parser involved, the code-execution context, or preview-pane exploitation. Claims beyond the published attack path would therefore be speculation.

Affected products

Microsoft’s affected-product data names the following Windows products in both 32-bit and 64-bit editions:

  • Microsoft 365 Apps for Enterprise
  • Microsoft Office 2019
  • Microsoft Office LTSC 2021
  • Microsoft Office LTSC 2024
  • Microsoft Outlook 2016

The advisory does not list new Outlook, Outlook on the web, Outlook for Mac, Outlook mobile, Microsoft 365 Apps for Business, or Office 2021/2024 retail as affected products. That omission should not be reversed into a broader claim: scope decisions should follow Microsoft’s current affected-product table and the actual product installed.

Fixed builds published for August 11

For Click-to-Run and volume-licensed Office deployments, administrators should use Microsoft’s Office security-release table to match the installed servicing channel to the correct secured build. The fixed builds published on August 11, 2026 include:

Office channel or productSecurity build
Microsoft 365 Current ChannelVersion 2607, build 20228.20190
Monthly Enterprise Channel2607 / 20228.20188; 2606 / 20131.20206; 2605 / 20026.20266
Semi-Annual Enterprise Channel receiving Monthly Enterprise builds2607 / 20228.20186
Semi-Annual Enterprise Channel2508 / 19127.20730
Office LTSC 2024 Volume Licensed2408 / 17932.20910
Office LTSC 2021 Volume Licensed2108 / 14334.20848
Office 2019 Volume Licensed1808 / 10417.20197
Outlook 2016 MSIKB5002755; fixed build 16.0.5565.1000

Microsoft says the Click-to-Run security updates do not require a restart. The Outlook 2016 MSI update may require one. KB5002755 applies to the MSI-based edition of Outlook 2016, not the Click-to-Run edition.

Office 2019 and Outlook 2016 reached end of support on October 14, 2025. Microsoft nevertheless published the relevant August 2026 fixes. Organizations still operating these versions should install the released security update and maintain a supported-version migration plan; the availability of this update does not restore full product support.

How the attack path changes the response

The confirmed attack path begins with a malicious Office file delivered to a user and succeeds only if the user opens it. That makes email, collaboration platforms, downloads, and other file-delivery paths relevant control points, but it does not make patching optional.

Until every affected installation is updated, DSE recommends treating unexpected Office attachments and links to Office documents as untrusted, maintaining attachment scanning and endpoint detection controls, and prioritizing users who routinely process external documents. These are DSE operational precautions derived from the published attack path; Microsoft has not published them as a formal workaround.

A practical patch-and-verify plan

  1. Inventory the actual Office estate. Record product, architecture, update technology, servicing channel, and current build. Do not rely only on a generic “Office installed” result.
  2. Prioritize exposed workflows. Start with users and teams that frequently open documents from customers, vendors, public mailboxes, file-transfer portals, or other external sources.
  3. Deploy the correct release. Use the August 11 Office security update for the installed servicing channel. For MSI-based Outlook 2016, deploy KB5002755.
  4. Verify the installed build. Confirm the resulting version against Microsoft’s channel-specific security table. A deployment job marked successful is not proof that the intended Office build is active.
  5. Monitor exceptions. Track endpoints that are offline, held by update rings, failing health checks, or running end-of-support Office versions. Give every exception an owner and due date.
  6. Investigate suspicious opens. If a user opened an unexpected Office file before the update, preserve the message and file metadata and review endpoint and email-security telemetry using the organization’s incident-response process.

Exploitation status as of August 12, 2026

At publication, Microsoft reported the vulnerability as not publicly disclosed, not exploited, and assessed exploitation as unlikely. CISA’s CVE enrichment records exploitation as “none,” and CVE-2026-70329 was not listed in CISA’s Known Exploited Vulnerabilities catalog when DSE checked on August 12.

Those are dated status statements, not guarantees about future activity. The presence of an official fix, the 8.8 score, and the potential for high impact support prompt remediation even without confirmed exploitation.

A note about Microsoft’s attack-vector wording

Microsoft’s published CVSS vector and the CVE Program record list the attack vector as Network (AV:N), and the CNA description says code execution is possible “over a network.” One sentence in Microsoft’s FAQ, however, refers to Local (AV:L). The same FAQ clearly states that the attacker sends a malicious file and the recipient must open it.

The most defensible description from the available source material is therefore: the malicious file can be delivered over a network, but exploitation requires the recipient to open it locally. DSE is not using the inconsistent FAQ sentence to infer a different exploit path and recommends monitoring the MSRC page for revisions.

Primary sources

Reviewed August 12, 2026. Vendor guidance and exploitation status can change; use the linked Microsoft advisory as the controlling source for later revisions.

Primary reference

Review the official source

Microsoft Security Response Center (MSRC) · Published August 11, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE