CVE-2026-21260: Microsoft Outlook Spoofing Vulnerability

Published Feb 10, 2026
·
Updated

Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

Other sources

Microsoft Outlook Spoofing Vulnerability

Microsoft

Affected Software

26 affected componentsFixes available
Microsoft Outlook 2016
Microsoft Outlook 2016
Microsoft Office LTSC 2024 for 64-bit editions
Microsoft 365 Apps for Enterprise
Microsoft SharePoint Server Subscription Edition
Microsoft Office LTSC 2021 for 32-bit editions
Microsoft Office LTSC 2021 for 64-bit editions
Microsoft Office 2019 for 64-bit editions
Microsoft SharePoint Enterprise Server 2016
Microsoft Office 2019 for 32-bit editions
Microsoft 365 Apps for Enterprise
Microsoft SharePoint Server 2019
Microsoft Office LTSC 2024 for 32-bit editions
Microsoft 365 Apps
Microsoft 365 Apps
Microsoft Office=2019
Microsoft Office=2019
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel=2021
Microsoft Office Long Term Servicing Channel=2024
Microsoft Office Long Term Servicing Channel=2024
Microsoft Outlook=2016
Microsoft Outlook=2016
Microsoft SharePoint Server<16.0.19127.20518
Microsoft SharePoint Server=2016
Microsoft SharePoint Server=2019

Event History

Feb 10, 2026
CVE Published
via Microsoft·04:00 PM
Data Sourced
via Microsoft·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·04:00 PM
Affected Software
Updated
via Microsoft·04:00 PM
Affected Software
Updated
via Microsoft·04:00 PM
Description
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionSeverity
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-21260?

CVE-2026-21260 has been rated as a critical vulnerability due to its potential to allow unauthorized access and spoofing in Microsoft Outlook.

2

How do I fix CVE-2026-21260?

To fix CVE-2026-21260, ensure that your affected Microsoft Outlook or other related Microsoft products are updated with the latest security patches provided by Microsoft.

3

Which Microsoft products are affected by CVE-2026-21260?

CVE-2026-21260 affects several versions of Microsoft Outlook, Office LTSC, Office 2019, and SharePoint products.

4

What are the potential impacts of exploiting CVE-2026-21260?

Exploiting CVE-2026-21260 can lead to information disclosure and unauthorized spoofing, allowing attackers to impersonate legitimate users in network communications.

5

Has Microsoft released a patch for CVE-2026-21260?

Yes, Microsoft has released patches to address CVE-2026-21260 that can be applied to the affected software versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203