Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)

Microsoft Office / Microsoft 365 Apps for Enterprise Remote (TL-2026-2659) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-09-26. It has no confirmed attribution, affects Microsoft Microsoft 365 Apps for Enterprise, references 1 CVE (CVE-2026-70125), maps to 9 MITRE ATT&CK techniques (T1203, T1204.001, T1204.002), and is covered by 9 detection rules and 10 indicators of compromise.

Key facts for TL-2026-2659

Threat ID
TL-2026-2659
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-26
Last reviewed
2026-09-26
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
all-industries-running-microsoft-365-apps
Target regions
global
Detection rules
9
Indicators of compromise
10

CVE-2026-70125 is a high-severity (CVSSv3.1 8.8) remote code execution vulnerability affecting Microsoft Outlook, Microsoft 365 Apps for Enterprise, and Microsoft Office LTSC 2021/2024. Microsoft's Security Update Guide titles it a "Microsoft Outlook Remote Code Execution Vulnerability" and requires user interaction to trigger; HKCERT's alert separately describes the trigger as a user opening a web page with specially crafted content in a vulnerable browser. No public proof-of-concept or in-the-wild exploitation has been reported, and a vendor patch is available via Windows Update / Microsoft Update Catalog.

How Microsoft Office / Microsoft 365 Apps for Enterprise Remote works

CVE-2026-70125 was reserved by MITRE on 2026-08-03 and published on 2026-09-23, several days after Microsoft's main September 2026 Patch Tuesday release (2026-09-08). Community trackers (TheWindowsUpdate.com, OffSeq Threat Radar) report that the underlying fix shipped with the September 2026 security updates but that the CVE entry itself was "inadvertently omitted" from the initial September 2026 Security Updates documentation and only surfaced afterward in the MSRC Security Update Guide, meaning organizations that already fully patched in September 2026 do not need further action beyond confirming the update installed.

Microsoft's own advisory title ("Microsoft Outlook Remote Code Execution Vulnerability") and the CVSS vector (AV:N/AC:L/PR:N/UI:R) both point to a client-side vulnerability that is triggered when a user interacts with attacker-supplied content inside Outlook/Office (e.g., a message or crafted file), consistent with no privileges required but user interaction required. HKCERT's Security Alert A26-09-39 (published 2026-09-24, drawing on the same underlying CVE) describes the trigger differently, as a remote attacker enticing a user to open a web page with specially crafted content in a vulnerable browser. Both narratives describe the same class of outcome — a user-interaction-gated, network-vector RCE reachable through content an attacker convinces the victim to open — and are documented here as the two distinct official characterizations found in primary/vendor sources; no source reconciles the exact technical trigger (email message vs. browser-rendered page) with a public technical write-up, and no CWE has been published by NVD/MSRC for this CVE as of last check.

Successful exploitation is rated CVSS impact C:H/I:H/A:H — full compromise of confidentiality, integrity, and availability on the affected endpoint, i.e., arbitrary code execution in the context of the logged-in user. The vulnerability affects Microsoft 365 Apps for Enterprise (builds 16.0.0 and 16.0.1), Microsoft Office LTSC 2021 (build 16.0.1), and Microsoft Office LTSC 2024 (build 16.0.0), on both 32-bit and x64 platforms. EPSS scores the 30-day exploitation probability at 0.44% (approximately the 36th percentile), it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public PoC code or confirmed in-the-wild exploitation has been identified by any of the trackers reviewed (GitHub CVE tracker, OffSeq, Strix.ai, TheHackerWire). A vendor-supplied patch is available and should be applied via Windows Update or the Microsoft Update Catalog.

MITRE ATT&CK techniques used in TL-2026-2659

Execution

T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1583.006 Acquire Infrastructure: Web Services; T1584.006 Compromise Infrastructure: Web Services; T1588.005 Obtain Capabilities: Exploits; T1588.006 Obtain Capabilities: Vulnerabilities

Affected products and versions in Microsoft Office / Microsoft 365 Apps for Enterprise Remote

  • Microsoft — Microsoft 365 Apps for Enterprise
    Vulnerable versions: 16.0.0; 16.0.1
    Fixed in: Click-to-Run build released with the September 2026 security update or later
  • Microsoft — Microsoft Office LTSC 2021
    Vulnerable versions: 16.0.1
    Fixed in: LTSC 2021 security update released 2026-09-23 or later
  • Microsoft — Microsoft Office LTSC 2024
    Vulnerable versions: 16.0.0
    Fixed in: LTSC 2024 security update released 2026-09-23 or later

Remediation for Microsoft Office / Microsoft 365 Apps for Enterprise Remote

Patches

  • Security update for Microsoft 365 Apps for Enterprise (builds 16.0.0/16.0.1 and later)
  • Security update for Microsoft Office LTSC 2021 (build 16.0.1 and later)
  • Security update for Microsoft Office LTSC 2024 (build 16.0.0 and later)

Immediate actions

  • Apply the Microsoft security update addressing CVE-2026-70125 for Microsoft 365 Apps for Enterprise, Office LTSC 2021, and Office LTSC 2024 via Windows Update or the Microsoft Update Catalog
  • Confirm the installed Click-to-Run build number is at or above the version that ships the fix, since organizations already fully patched for September 2026 may already be protected despite the CVE's late disclosure
  • Prioritize endpoints where users regularly open external email or browse untrusted web content from within Outlook/Office

Workarounds

  • No official workaround has been published by Microsoft or HKCERT; the documented remediation is installing the vendor security update

Longer-term hardening

  • Enable automatic updates for Microsoft 365 Apps to reduce exposure windows for RCE vulnerabilities disclosed outside the normal Patch Tuesday cadence
  • Track the MSRC Security Update Guide entry for CVE-2026-70125 for revisions, given Microsoft itself noted the CVE was inadvertently omitted from the initial September 2026 Security Updates documentation
  • Monitor CISA KEV and HKCERT/GovCERT.HK for any future change in exploitation-in-the-wild status for this CVE

CVEs associated with Microsoft Office / Microsoft 365 Apps for Enterprise Remote

CVE-2026-70125

Timeline of Microsoft Office / Microsoft 365 Apps for Enterprise Remote

  • CVE-2026-70125 is reserved in the MITRE CVE program ahead of public disclosure.
  • Microsoft's main September 2026 Patch Tuesday security updates ship; the underlying fix for CVE-2026-70125 is reported to have been included, but the CVE entry itself is not yet documented.
  • Community update trackers (TheWindowsUpdate.com, GitHub CVE issue tracker) publish notices summarizing the newly disclosed CVE-2026-70125 and its patch status.
  • CVE-2026-70125 is published via the MSRC Security Update Guide, titled 'Microsoft Outlook Remote Code Execution Vulnerability', with a note that it was inadvertently omitted from the September 2026 Security Updates documentation.
  • HKCERT/GovCERT.HK publishes Security Alert A26-09-39 covering CVE-2026-70125, describing the exploitation scenario as a user opening a web page with specially crafted content in a vulnerable browser.
  • NVD/vulnerability-intelligence trackers record CVE-2026-70125 as last modified, with CVSS 3.1 base score 8.8 and status 'Awaiting Analysis'; the CVE is confirmed absent from the CISA KEV catalog as of this date.
  • Third-party CVE trackers (Strix.ai) show a last-updated timestamp for CVE-2026-70125, still reporting no known public exploit and no confirmed in-the-wild exploitation.

Sources cited for Microsoft Office / Microsoft 365 Apps for Enterprise Remote

More in vulnerability

Detection coverage for TL-2026-2659

As of 2026-09-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2659 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats