Microsoft Outlook Flaw Lets Hackers Run Code via Malicious Email: What Users Must Do

CERT-In has issued a high-severity advisory on CVE-2026-70125, a flaw in Microsoft Outlook that lets remote attackers run arbitrary code through a crafted file or email. Users of Microsoft 365 Apps and Office LTSC 2021 and 2024 have been asked to patch immediately.

Microsoft Outlook Logo (Photo Credit; Wikimedia Commons)

The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity advisory about a serious security flaw in Microsoft 365 applications, including Microsoft Outlook, that could let remote attackers take control of vulnerable systems. Tracked as CVE-2026-70125, the bug allows arbitrary code execution, which means a hacker could compromise a targeted device and gain access to sensitive personal and corporate data. The national cyber security agency has asked individual users and enterprise organisations running affected versions to install Microsoft's official security patches without delay.

Microsoft has already released updates that fix the problem, so the risk mainly applies to those who have not yet updated.

How to Update Microsoft Office and Outlook

Individual users can open any Office application, such as Word or Outlook, go to File > Account and select Update Options > Update Now.

Organisations that rely on centralised patch management tools like Microsoft Intune, SCCM or Windows Server Update Services should confirm that their endpoints carry the latest security release. Microsoft Unveils Biggest Copilot Overhaul With Home, Code and Autopilot Features.

CERT-In has also stressed the need to use genuine, licensed software, as this ensures users keep receiving security definitions and critical updates.

How the Vulnerability Works

CERT-In says the flaw comes from improper input validation in Microsoft Outlook. An attacker only needs to send a specially crafted file or email message to a victim. If an unpatched client processes it, the exploit triggers remote code execution.

According to the agency, this could let attackers run unauthorised commands, steal sensitive files, tamper with calendar and email records, or push further malicious payloads across local networks. Microsoft Launches 4th Cloud Region in India, Expands AI Infrastructure With USD 20.5B Investment.

'Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code and compromise affected systems on the targeted system,' CERT-In stated in its vulnerability note.

Which Versions Are Affected

The advisory covers both 32-bit and 64-bit editions of the following software:

  • Microsoft 365 Apps for Enterprise
  • Microsoft Office LTSC 2021
  • Microsoft Office LTSC 2024

Since Outlook is a central tool for corporate email, scheduling and document sharing, unpatched enterprise setups are especially exposed to targeted spear-phishing and file-based attacks.

CERT-In's Advice

CERT-In regularly tracks zero-day bugs and published vulnerabilities to protect Indian cyberspace. The agency advises users to keep to regular update cycles, calling them the primary defence against known exploits.

Rating:3

TruLY Score 3 – Believable; Needs Further Research | On a Trust Scale of 0-5 this article has scored 3 on LatestLY, this article appears believable but may need additional verification. It is based on reporting from news websites or verified journalists (News Reports), but lacks supporting official confirmation. Readers are advised to treat the information as credible but continue to follow up for updates or confirmations

(The above story first appeared on LatestLY on Sep 28, 2026 11:13 PM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).

Share Now

Share Now