Threat reportVulnerabilityTL-2026-1991

CVE-2026-70329: Microsoft Outlook Remote Code Execution via Integer Overflow

highPATCHED

CVE-2026-70329 (TL-2026-1991) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-08-11. It has no confirmed attribution, affects Microsoft 365 Apps for Enterprise, references 1 CVE (CVE-2026-70329), maps to 10 MITRE ATT&CK techniques (T1036, T1203, T1204.002), and is covered by 9 detection rules and 11 indicators of compromise.

CVSS
8.8/10High
CVEs
1Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
11Indicators of compromise

Key facts for TL-2026-1991

Threat ID
TL-2026-1991
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
11

How CVE-2026-70329 works

Microsoft patched CVE-2026-70329, a CVSS 8.8 integer overflow/wraparound (CWE-190) vulnerability in Outlook that allows an unauthorized attacker to execute code over a network when a victim opens a malicious Office file, typically disguised as an email attachment. Fixed in the August 2026 Patch Tuesday release; Microsoft rates exploitation as unlikely and reports no in-the-wild exploitation or public PoC.

CVE-2026-70329 is an integer overflow or wraparound weakness (CWE-190) in Microsoft Office Outlook that leads to memory corruption and remote code execution. Per the NVD description, an unauthorized attacker can execute code over a network, but exploitation requires user interaction: the victim must open a specially crafted Office file, typically delivered as an email attachment via a phishing-style lure. Cyber Security News' technical summary describes the mechanism directly: "the integer overflow bug can be triggered to corrupt memory and hijack program execution," with the resulting impact scoped to whatever privileges the logged-in victim account holds. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) confirms a network attack vector, low attack complexity, no privileges required, required user interaction, an unchanged scope, and high impact to confidentiality, integrity, and availability once the flaw is triggered.

Microsoft's own Security Update Guide FAQ clarifies terminology that is easy to misread: "the 'Remote' in the title refers to the attacker's location, not the attack vector" -- the exploit code itself executes locally on the victim's machine once the malicious file is opened (sometimes termed Arbitrary Code Execution, or ACE). MSRC's FAQ states the attack in plain terms: the attacker must "send a user a malicious Office file and convince them to open it." Notably, MSRC's own severity label for this entry is "Important" (its internal four-tier scale), while the CVSS 3.1 numeric score of 8.8 maps to the qualitative band "High" under NVD/FIRST scoring conventions -- both labels describe the same vulnerability and are not in conflict, but readers cross-referencing Microsoft's release notes against NVD should expect the naming difference. Microsoft additionally publishes a Temporal CVSS score of 7.7 (reflecting the lack of a public exploit and the 'Unlikely' exploitation rating pulling the Base 8.8 downward).

The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024 (all 32-bit and 64-bit), and standalone Microsoft Outlook 2016 (vulnerable range 16.0.0.0-16.0.5565.1000). Microsoft published the advisory and shipped fixes on August 11, 2026 as part of a Patch Tuesday release; outlets diverge on the exact total CVE count for the month (BleepingComputer reports 400 flaws/42 Critical; Cyber Security News' broader roundup reports 394; a third aggregator reports 421 including two republished non-Microsoft TPM CVEs) -- a normal artifact of different outlets snapshotting the MSRC catalog at slightly different times and applying different inclusion rules, not a discrepancy specific to this CVE. Click-to-Run editions (365 Apps for Enterprise, Office 2019/2021/2024 retail) update automatically to Version 2607 Build 20228.20190 (Current Channel) or the equivalent build for their channel; standalone Outlook 2016 MSI installations require the manually-deployed KB5002755 update, which brings the build to 16.0.5565.1000.

Microsoft credits an anonymous researcher via its Coordinated Vulnerability Disclosure (CVD) program and rates exploitation "unlikely," noting that this assessment could shift if proof-of-concept code becomes public. No PoC has been published (confirmed absent from GitHub PoC-tracking repositories as of this research pass) and the vulnerability is absent from the CISA Known Exploited Vulnerabilities (KEV) catalog as of the August 11, 2026 catalog version, consistent with Microsoft's exploitability rating. The same Patch Tuesday cycle separately fixed CVE-2026-62882 (an unrelated Outlook spoofing flaw, CVSS 4.3) and a cluster of Excel/PowerPoint/Word information-disclosure and RCE CVEs (including CVE-2026-70328, -70327, -70318, -70325, -70322, -70320, -70316, -70312, -70311, -70310, -70319, -66806); none of these is described by any reviewed source as sharing an exploitation chain or root cause with CVE-2026-70329. The month's headline zero-day was CVE-2026-68820, an actively-exploited Windows Ancillary Function Driver (AFD) elevation-of-privilege flaw (CVSS 7.0) in a driver with a recurring history of zero-days since August 2024; two sibling AFD EoP flaws in the same batch (CVE-2026-61348, CVE-2026-70307) were separately rated 'Exploitation More Likely.' Reviewed sources do not corroborate a Lazarus/FudModule attribution for CVE-2026-68820 independent of the harness's original hunt sourcing, and in any case that flaw is unconnected to the Outlook RCE documented here.

Because Microsoft did not publish a detailed technical write-up of the exploit primitive (no discussion of heap layout, ROP chains, or specific parser code paths -- standard practice for a flaw with no public PoC and an 'Unlikely' rating), and no independent researcher has published exploit analysis, the MITRE ATT&CK mapping below is intentionally bounded to what the primary sources actually state rather than the full theoretical playbook for the vulnerability class. A re-verification pass against MSRC's raw FAQ API, NVD, and Zero Day Initiative's August 2026 review confirms no additional technical detail has since surfaced: the MSRC FAQ discloses only the two lines already reflected here (an attacker must send a user a malicious Office file and convince them to open it; and the 'Remote' terminology clarification), and NVD/ZDI add no mechanism detail beyond the CVSS vector and CWE-190 classification already captured. CVE-2026-70329 should also not be confused with the unrelated, more severe CVE-2026-40361 disclosed in the same August 2026 batch: a zero-click Word rendering-engine RCE (wwlib.dll, CVSS 8.4) triggerable via Outlook's Preview Pane with no user interaction, rated 'Exploitation More Likely'. CVE-2026-70329 by contrast requires the victim to explicitly open the crafted Office file (CVSS UI:R) and remains rated 'Exploitation Unlikely'. A follow-up sourcing pass against Cyber Security News, Zero Day Initiative's write-up, the raw MSRC FAQ API, and NVD's CVE 2.0 API confirmed no further mechanism detail exists beyond what is already captured above (no macro/OLE/RTF/preview-pane specifics, no ROP-chain or heap-layout discussion, no PoC on GitHub PoC-tracking indexes). Given this evidentiary ceiling, the MITRE list below stays at 10 well-sourced techniques across 4 tactics -- expanded only with the two weaponization/delivery-channel steps MSRC's own FAQ text directly implies (obtaining, not just developing, the malicious document; and the email-sending identity required to 'send a user a malicious Office file') -- rather than padding toward a higher count with unstated post-exploitation techniques (e.g. command and control, lateral movement, or persistence) that no reviewed source attributes to this specific CVE.

MITRE ATT&CK techniques used in TL-2026-1991

Defense Evasion

T1036 Masquerading

Execution

T1203 Exploitation for Client Execution; T1204.002 User Execution: Malicious File

Initial Access

T1566.001 Phishing: Spearphishing Attachment

Resource Development

T1585.002 Establish Accounts: Email Accounts; T1587.001 Develop Capabilities: Malware; T1587.004 Develop Capabilities: Exploits; T1588.001 Obtain Capabilities: Malware; T1588.005 Obtain Capabilities: Exploits; T1588.006 Obtain Capabilities: Vulnerabilities

Affected products and versions in CVE-2026-70329

  • Microsoft — 365 Apps for Enterprise
    Vulnerable versions: 32-bit and 64-bit, prior to August 2026 security update
    Fixed in: Current Channel Version 2607 Build 20228.20190 (or channel-equivalent build)
  • Microsoft — Office 2019
    Vulnerable versions: 32-bit and 64-bit, prior to August 2026 security update
    Fixed in: August 2026 security update
  • Microsoft — Office LTSC 2021
    Vulnerable versions: 32-bit and 64-bit, prior to August 2026 security update
    Fixed in: August 2026 security update
  • Microsoft — Office LTSC 2024
    Vulnerable versions: 32-bit and 64-bit, prior to August 2026 security update
    Fixed in: August 2026 security update
  • Microsoft — Outlook 2016 (standalone, MSI)
    Vulnerable versions: 16.0.0.0 - 16.0.5565.1000
    Fixed in: 16.0.5565.1000 via KB5002755

Remediation for CVE-2026-70329

Patches

  • KB5002755 -- standalone Outlook 2016 (MSI) -> build 16.0.5565.1000
  • Current Channel Click-to-Run -> Version 2607, Build 20228.20190
  • Monthly Enterprise Channel -> Version 2607 Build 20228.20188 / Version 2606 Build 20131.20206 / Version 2605 Build 20026.20266
  • Semi-Annual Enterprise Channel -> Version 2607 Build 20228.20186 / Version 2508 Build 19127.20730

Immediate actions

  • Apply the August 2026 Microsoft Office/Outlook security update for the affected release channel; Click-to-Run editions update automatically
  • For standalone Outlook 2016 MSI installations, manually deploy KB5002755 (no auto-update)
  • Filter or sandbox inbound email attachments containing Office file formats at the mail gateway pending patch deployment

Longer-term hardening

  • Migrate any remaining standalone Outlook 2016 MSI deployments to a Click-to-Run channel for automatic future patching
  • Enforce Protected View and attachment-sandboxing policies for Office files received from external senders
  • Track Microsoft's exploitability index (currently 'Unlikely', Temporal CVSS 7.7) and public PoC/exploit trackers (e.g. GitHub CVE-PoC indexes) for CVE-2026-70329 in case the rating changes once exploit code emerges publicly

CVEs associated with CVE-2026-70329

CVE-2026-70329

Weaknesses (CWE) in CVE-2026-70329

CWE-190

Timeline of CVE-2026-70329

  • Cyber Security News publishes a separate patch-cycle roundup ('394 Vulnerabilities Fixed, Including 3 Zero-Days') listing CVE-2026-70329 as an Important-severity Outlook RCE within the 98 Office-family CVEs (23.3% of the month's total) fixed alongside 236 Windows CVEs.
  • Lansweeper publishes its own August 2026 Patch Tuesday summary (669 aggregated fixes, 82 Critical in its counting methodology), without singling out CVE-2026-70329 for special mention.
  • Tenable publishes its August 2026 Patch Tuesday roundup, centered on the actively-exploited AFD zero-day CVE-2026-68820 and its two 'Exploitation More Likely' siblings (CVE-2026-61348, CVE-2026-70307); CVE-2026-70329 is not separately highlighted, consistent with its lower exploitation-likelihood rating.
  • BleepingComputer reports on Microsoft's August 2026 Patch Tuesday (400 flaws total, 42 Critical), listing CVE-2026-70329 as an Important-severity Outlook RCE alongside the actively-exploited zero-day CVE-2026-68820.
  • Zero Day Initiative publishes its August 2026 Security Update Review, cataloguing CVE-2026-70329 as an Important-severity, non-public, non-exploited RCE among the month's new Microsoft CVEs, alongside sibling PowerPoint RCE CVE-2026-70313.
  • Microsoft Corporation submits CVE-2026-70329 to NVD (CVSS 3.1 8.8, CWE-190) for enrichment.
  • Microsoft ships fixes across all affected channels: Click-to-Run editions update automatically to Version 2607 Build 20228.20190 (or channel-equivalent build); standalone Outlook 2016 receives KB5002755, bringing it to build 16.0.5565.1000.
  • CVE-2026-70329 is registered with the MITRE CVE Program (cve.org) as the canonical identifier for the Outlook integer-overflow flaw.
  • Microsoft publishes the CVE-2026-70329 advisory in the MSRC Security Update Guide as part of the August 2026 Patch Tuesday release, rating it 'Important' severity with an 'Unlikely' exploitability assessment.
  • Cyber Security News publishes its dedicated technical article on CVE-2026-70329, the source article that triggered this hunt.

Sources cited for CVE-2026-70329

Detection coverage for TL-2026-1991

As of 2026-08-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1991 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
11 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats