Known Vulnerabilities for Outlook by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Outlook" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-80084 json | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-80073 json | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-78525 json | Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-78520 json | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-78519 json | Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-78509 json | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-70329 json | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-69629 json | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-62882 json | Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a n... | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-61280 json | Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Outlook Sync Win 32). Support... | Not Provided | 2026-07-21 | 2026-07-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Outlook | xp | |||
| Application | Microsoft | Outlook | 98 | |||
| Application | Microsoft | Outlook | 97 | |||
| Application | Microsoft | Outlook | 3.33.0 | |||
| Application | Microsoft | Outlook | 3.32.0 | |||
| Application | Microsoft | Outlook | 3.31.0 | |||
| Application | Microsoft | Outlook | 3.30.0 | |||
| Application | Microsoft | Outlook | 3.29.0 | |||
| Application | Microsoft | Outlook | 3.28.0 | |||
| Application | Microsoft | Outlook | 3.27.1 | |||
| Application | Microsoft | Outlook | 3.27.0 | |||
| Application | Microsoft | Outlook | 3.26.0 | |||
| Application | Microsoft | Outlook | 3.25.0 | |||
| Application | Microsoft | Outlook | 3.24.1 | |||
| Application | Microsoft | Outlook | 3.24.0 | |||
| Application | Microsoft | Outlook | 3.23.0 | |||
| Application | Microsoft | Outlook | 3.22.1 | |||
| Application | Microsoft | Outlook | 3.22.0 | |||
| Application | Microsoft | Outlook | 3.21.0 | |||
| Application | Microsoft | Outlook | 3.20.0 |