Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)
Microsoft Office / Microsoft 365 Apps for Enterprise Remote (TL-2026-2659) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-09-26. It has no confirmed attribution, affects Microsoft Microsoft 365 Apps for Enterprise, references 1 CVE (CVE-2026-70125), maps to 9 MITRE ATT&CK techniques (T1203, T1204.001, T1204.002), and is covered by 9 detection rules and 10 indicators of compromise.
Key facts for TL-2026-2659
- Threat ID
- TL-2026-2659
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-26
- Last reviewed
- 2026-09-26
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all-industries-running-microsoft-365-apps
- Target regions
- global
- Detection rules
- 9
- Indicators of compromise
- 10
CVE-2026-70125 is a high-severity (CVSSv3.1 8.8) remote code execution vulnerability affecting Microsoft Outlook, Microsoft 365 Apps for Enterprise, and Microsoft Office LTSC 2021/2024. Microsoft's Security Update Guide titles it a "Microsoft Outlook Remote Code Execution Vulnerability" and requires user interaction to trigger; HKCERT's alert separately describes the trigger as a user opening a web page with specially crafted content in a vulnerable browser. No public proof-of-concept or in-the-wild exploitation has been reported, and a vendor patch is available via Windows Update / Microsoft Update Catalog.
How Microsoft Office / Microsoft 365 Apps for Enterprise Remote works
CVE-2026-70125 was reserved by MITRE on 2026-08-03 and published on 2026-09-23, several days after Microsoft's main September 2026 Patch Tuesday release (2026-09-08). Community trackers (TheWindowsUpdate.com, OffSeq Threat Radar) report that the underlying fix shipped with the September 2026 security updates but that the CVE entry itself was "inadvertently omitted" from the initial September 2026 Security Updates documentation and only surfaced afterward in the MSRC Security Update Guide, meaning organizations that already fully patched in September 2026 do not need further action beyond confirming the update installed.
Microsoft's own advisory title ("Microsoft Outlook Remote Code Execution Vulnerability") and the CVSS vector (AV:N/AC:L/PR:N/UI:R) both point to a client-side vulnerability that is triggered when a user interacts with attacker-supplied content inside Outlook/Office (e.g., a message or crafted file), consistent with no privileges required but user interaction required. HKCERT's Security Alert A26-09-39 (published 2026-09-24, drawing on the same underlying CVE) describes the trigger differently, as a remote attacker enticing a user to open a web page with specially crafted content in a vulnerable browser. Both narratives describe the same class of outcome — a user-interaction-gated, network-vector RCE reachable through content an attacker convinces the victim to open — and are documented here as the two distinct official characterizations found in primary/vendor sources; no source reconciles the exact technical trigger (email message vs. browser-rendered page) with a public technical write-up, and no CWE has been published by NVD/MSRC for this CVE as of last check.
Successful exploitation is rated CVSS impact C:H/I:H/A:H — full compromise of confidentiality, integrity, and availability on the affected endpoint, i.e., arbitrary code execution in the context of the logged-in user. The vulnerability affects Microsoft 365 Apps for Enterprise (builds 16.0.0 and 16.0.1), Microsoft Office LTSC 2021 (build 16.0.1), and Microsoft Office LTSC 2024 (build 16.0.0), on both 32-bit and x64 platforms. EPSS scores the 30-day exploitation probability at 0.44% (approximately the 36th percentile), it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public PoC code or confirmed in-the-wild exploitation has been identified by any of the trackers reviewed (GitHub CVE tracker, OffSeq, Strix.ai, TheHackerWire). A vendor-supplied patch is available and should be applied via Windows Update or the Microsoft Update Catalog.
MITRE ATT&CK techniques used in TL-2026-2659
Execution
T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
T1583.006 Acquire Infrastructure: Web Services; T1584.006 Compromise Infrastructure: Web Services; T1588.005 Obtain Capabilities: Exploits; T1588.006 Obtain Capabilities: Vulnerabilities
Affected products and versions in Microsoft Office / Microsoft 365 Apps for Enterprise Remote
- Microsoft — Microsoft 365 Apps for Enterprise
Vulnerable versions: 16.0.0; 16.0.1
Fixed in: Click-to-Run build released with the September 2026 security update or later - Microsoft — Microsoft Office LTSC 2021
Vulnerable versions: 16.0.1
Fixed in: LTSC 2021 security update released 2026-09-23 or later - Microsoft — Microsoft Office LTSC 2024
Vulnerable versions: 16.0.0
Fixed in: LTSC 2024 security update released 2026-09-23 or later
Remediation for Microsoft Office / Microsoft 365 Apps for Enterprise Remote
Patches
- Security update for Microsoft 365 Apps for Enterprise (builds 16.0.0/16.0.1 and later)
- Security update for Microsoft Office LTSC 2021 (build 16.0.1 and later)
- Security update for Microsoft Office LTSC 2024 (build 16.0.0 and later)
Immediate actions
- Apply the Microsoft security update addressing CVE-2026-70125 for Microsoft 365 Apps for Enterprise, Office LTSC 2021, and Office LTSC 2024 via Windows Update or the Microsoft Update Catalog
- Confirm the installed Click-to-Run build number is at or above the version that ships the fix, since organizations already fully patched for September 2026 may already be protected despite the CVE's late disclosure
- Prioritize endpoints where users regularly open external email or browse untrusted web content from within Outlook/Office
Workarounds
- No official workaround has been published by Microsoft or HKCERT; the documented remediation is installing the vendor security update
Longer-term hardening
- Enable automatic updates for Microsoft 365 Apps to reduce exposure windows for RCE vulnerabilities disclosed outside the normal Patch Tuesday cadence
- Track the MSRC Security Update Guide entry for CVE-2026-70125 for revisions, given Microsoft itself noted the CVE was inadvertently omitted from the initial September 2026 Security Updates documentation
- Monitor CISA KEV and HKCERT/GovCERT.HK for any future change in exploitation-in-the-wild status for this CVE
CVEs associated with Microsoft Office / Microsoft 365 Apps for Enterprise Remote
Timeline of Microsoft Office / Microsoft 365 Apps for Enterprise Remote
- CVE-2026-70125 is reserved in the MITRE CVE program ahead of public disclosure.
- Microsoft's main September 2026 Patch Tuesday security updates ship; the underlying fix for CVE-2026-70125 is reported to have been included, but the CVE entry itself is not yet documented.
- Community update trackers (TheWindowsUpdate.com, GitHub CVE issue tracker) publish notices summarizing the newly disclosed CVE-2026-70125 and its patch status.
- CVE-2026-70125 is published via the MSRC Security Update Guide, titled 'Microsoft Outlook Remote Code Execution Vulnerability', with a note that it was inadvertently omitted from the September 2026 Security Updates documentation.
- HKCERT/GovCERT.HK publishes Security Alert A26-09-39 covering CVE-2026-70125, describing the exploitation scenario as a user opening a web page with specially crafted content in a vulnerable browser.
- NVD/vulnerability-intelligence trackers record CVE-2026-70125 as last modified, with CVSS 3.1 base score 8.8 and status 'Awaiting Analysis'; the CVE is confirmed absent from the CISA KEV catalog as of this date.
- Third-party CVE trackers (Strix.ai) show a last-updated timestamp for CVE-2026-70125, still reporting no known public exploit and no confirmed in-the-wild exploitation.
Sources cited for Microsoft Office / Microsoft 365 Apps for Enterprise Remote
- HKCERT Security Alert A26-09-39
- CVE-2026-70125 - Security Update Guide - Microsoft Outlook Remote Code Execution Vulnerability
- Microsoft 365 Apps updates - Security updates
- Office 365 ProPlus (Microsoft 365 Apps) security updates
- CVE-2026-70125 Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2026-70125: Remote Code Execution in Microsoft 365 Apps for Enterprise - Threat Radar
- CVE-2026-70125: Microsoft 365 Apps for Enterprise Vulnerability
- CVE-2026-70125 PoC, Exploit Status & Vulnerability Details
- [VULN ALERT] CVE-2026-70125 (risk 31.0) - microsoft/office
- CISA Known Exploited Vulnerabilities Catalog
More in vulnerability
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37)
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40
- Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses (CVE-2026-13016, CVE-2026-86857-86860)
- Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin skip_block_zeroing residual block reuse
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS
Detection coverage for TL-2026-2659
As of 2026-09-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2659 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.