microsoftCVE-2026-100208
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
High7.5CVE-2026-100208 · Published Sep 25, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Microsoft 365 Apps for Enterprise Vendor | >= 16.0.1, < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| Microsoft Office LTSC 2021 Vendor | >= 16.0.1, < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| Microsoft Office LTSC 2024 Vendor | >= 16.0.0, < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
Details and references
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- no source yet
- Weakness
- CWE-190
More microsoft advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Microsoft Office Outlook Remote Code Execution Vulnerability CVE-2026-70125High8.8fixed in Microsoft 365 Apps for Enterprise https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2021 https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2024 https://aka.ms/OfficeSecurityRelea | High8.8 | Microsoft 365 Apps for Enterprise https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2021 https://aka.ms/OfficeSecurityReleases, Microsoft Office LTSC 2024 https://aka.ms/OfficeSecurityRelea |
| Sep 18 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. CVE-2026-88097High8.1fixed in Microsoft Edge (Chromium-based) 153.0.4234.46 | High8.1 | Microsoft Edge (Chromium-based) 153.0.4234.46 |
| Sep 18 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network. CVE-2026-85878Critical9.9no fix yet | Critical9.9 | No fix yet |
| Sep 18 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. CVE-2026-85887High7.7no fix yet | High7.7 | No fix yet |
| Sep 18 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network. CVE-2026-83946High8.2no fix yet | High8.2 | No fix yet |
| Sep 18 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. CVE-2026-69843Critical10.0no fix yet | Critical10.0 | No fix yet |