Threat Intelligence / CVE / CVE-2026-33824

CVE-2026-33824

CVSS 8.4 (HIGH) · EPSS 0.1% · Priority 5/10 · Published 2026-04-14

As of 2026-04-14, CVE-2026-33824 is a CVSS 8.4 (HIGH-severity) vulnerability. EPSS exploitation probability 0.1%. Threadlinqs Intelligence tracks 4 threats exploiting it.

Last updated: 2026-04-14

A remote code execution vulnerability exists in Microsoft Office and Outlook due to an OLE object handling bug. An attacker could exploit this vulnerability by sending a specially crafted email; previewing the email in the Outlook Preview Pane is sufficient to trigger exploitation without requiring the user to open the message. Successful exploitation allows arbitrary code execution in the context of the user. The vulnerability was disclosed as part of the Microsoft April 2026 Patch Tuesday release, which remediated 167 vulnerabilities. This CVE was rated Critical severity with a CVSS 8.4 base score. The Preview Pane attack vector significantly increases exploitability as no user interaction beyond viewing the email preview is required.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-843

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2026-33824 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.