CVE-2026-77493 – Microsoft Office Outlook Remote Code Execution Vulnerability

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“A malicious email can turn the Outlook Reading Pane into a path for remote code execution without a click.”

CVE-2026-77493 is a critical remote code execution vulnerability caused by a double-free memory handling issue in Microsoft Office Outlook. An attacker can send a specially crafted email to a target, and simply viewing that message in the Outlook Reading Pane can trigger the vulnerability. Successful exploitation could allow attacker-controlled code to execute on the recipient’s system. The affected Microsoft product is identified as Microsoft Office Outlook; the affected-software table specifically lists supported Windows client and Windows Server versions.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-415
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.