CVE Tools

Microsoft Outlook

29 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Microsoft Outlook, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Microsoft Outlook CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Microsoft Outlook CVEs per month
MonthCVEs
2024-101
2024-110
2024-121
2025-011
2025-021
2025-030
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-051
2026-060
2026-070
2026-080
2026-090

Severity

How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High1862%
  • Medium1138%

Latest CVEs

The 15 most recently published vulnerabilities affecting Microsoft Outlook.

  1. CVE-2026-42893Microsoft Outlook for iOS Tampering Vulnerability7.4
  2. CVE-2025-29805Outlook for Android Information Disclosure Vulnerability7.5
  3. CVE-2025-21259Microsoft Outlook Spoofing Vulnerability5.3
  4. CVE-2025-21361Microsoft Outlook Remote Code Execution Vulnerability7.8
  5. CVE-2024-42220A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious ap...7.1
  6. CVE-2024-43604Outlook for Android Elevation of Privilege Vulnerability5.7
  7. CVE-2024-43482Microsoft Outlook for iOS Information Disclosure Vulnerability6.5
  8. BDU:2024-04811Уязвимость почтового клиента Microsoft Outlook для операционных систем Windows, связанная с возможностью подмены адреса электрорнной почты, позволяющая нарушителю проводить фишинг-атаки8.8
  9. CVE-2024-20670Outlook for Windows Spoofing Vulnerability8.1
  10. CVE-2024-26204Outlook for Android Information Disclosure Vulnerability7.5
  11. BDU:2021-05358Уязвимость компонента Address Book почтового клиента Microsoft Outlook, позволяющая нарушителю проводить спуфинг-атаки6.3
  12. CVE-2020-1349A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.7.8
  13. CVE-2020-0760A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from ...8.8
  14. CVE-2020-0696A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.6.5
  15. CVE-2019-1218Outlook iOS Spoofing Vulnerability5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store