CVE-2026-21260: Microsoft Outlook Spoofing Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
Other sources
Microsoft Outlook Spoofing Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21260?
CVE-2026-21260 has been rated as a critical vulnerability due to its potential to allow unauthorized access and spoofing in Microsoft Outlook.
How do I fix CVE-2026-21260?
To fix CVE-2026-21260, ensure that your affected Microsoft Outlook or other related Microsoft products are updated with the latest security patches provided by Microsoft.
Which Microsoft products are affected by CVE-2026-21260?
CVE-2026-21260 affects several versions of Microsoft Outlook, Office LTSC, Office 2019, and SharePoint products.
What are the potential impacts of exploiting CVE-2026-21260?
Exploiting CVE-2026-21260 can lead to information disclosure and unauthorized spoofing, allowing attackers to impersonate legitimate users in network communications.
Has Microsoft released a patch for CVE-2026-21260?
Yes, Microsoft has released patches to address CVE-2026-21260 that can be applied to the affected software versions.