Microsoft Outlook Flaw Lets Hackers Run Code via Malicious Email: What Users Must Do
CERT-In has issued a high-severity advisory on CVE-2026-70125, a flaw in Microsoft Outlook that lets remote attackers run arbitrary code through a crafted file or email. Users of Microsoft 365 Apps and Office LTSC 2021 and 2024 have been asked to patch immediately.
The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity advisory about a serious security flaw in Microsoft 365 applications, including Microsoft Outlook, that could let remote attackers take control of vulnerable systems. Tracked as CVE-2026-70125, the bug allows arbitrary code execution, which means a hacker could compromise a targeted device and gain access to sensitive personal and corporate data. The national cyber security agency has asked individual users and enterprise organisations running affected versions to install Microsoft's official security patches without delay.
Microsoft has already released updates that fix the problem, so the risk mainly applies to those who have not yet updated.
How to Update Microsoft Office and Outlook
Individual users can open any Office application, such as Word or Outlook, go to File > Account and select Update Options > Update Now.
Organisations that rely on centralised patch management tools like Microsoft Intune, SCCM or Windows Server Update Services should confirm that their endpoints carry the latest security release. Microsoft Unveils Biggest Copilot Overhaul With Home, Code and Autopilot Features.
CERT-In has also stressed the need to use genuine, licensed software, as this ensures users keep receiving security definitions and critical updates.
How the Vulnerability Works
CERT-In says the flaw comes from improper input validation in Microsoft Outlook. An attacker only needs to send a specially crafted file or email message to a victim. If an unpatched client processes it, the exploit triggers remote code execution.
According to the agency, this could let attackers run unauthorised commands, steal sensitive files, tamper with calendar and email records, or push further malicious payloads across local networks. Microsoft Launches 4th Cloud Region in India, Expands AI Infrastructure With USD 20.5B Investment.
'Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code and compromise affected systems on the targeted system,' CERT-In stated in its vulnerability note.
Which Versions Are Affected
The advisory covers both 32-bit and 64-bit editions of the following software:
- Microsoft 365 Apps for Enterprise
- Microsoft Office LTSC 2021
- Microsoft Office LTSC 2024
Since Outlook is a central tool for corporate email, scheduling and document sharing, unpatched enterprise setups are especially exposed to targeted spear-phishing and file-based attacks.
CERT-In's Advice
CERT-In regularly tracks zero-day bugs and published vulnerabilities to protect Indian cyberspace. The agency advises users to keep to regular update cycles, calling them the primary defence against known exploits.
(The above story first appeared on LatestLY on Sep 28, 2026 11:13 PM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).