CVE-2026-77493 – Microsoft Office Outlook Remote Code Execution Vulnerability
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“A malicious email can turn the Outlook Reading Pane into a path for remote code execution without a click.”
CVE-2026-77493 is a critical remote code execution vulnerability caused by a double-free memory handling issue in Microsoft Office Outlook. An attacker can send a specially crafted email to a target, and simply viewing that message in the Outlook Reading Pane can trigger the vulnerability. Successful exploitation could allow attacker-controlled code to execute on the recipient’s system. The affected Microsoft product is identified as Microsoft Office Outlook; the affected-software table specifically lists supported Windows client and Windows Server versions.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-415
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.