CVE Tools

Outlook

125 CVEs tracked. 5 of them are in CISA KEV.

This hub aggregates every CVE we track for Outlook, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Outlook CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Outlook CVEs per month
MonthCVEs
2024-101
2024-110
2024-121
2025-012
2025-021
2025-030
2025-041
2025-050
2025-061
2025-071
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-031
2026-040
2026-051
2026-060
2026-070
2026-082
2026-093

Severity

How the 125 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical108%
  • High5746%
  • Medium5846%

Latest CVEs

The 15 most recently published vulnerabilities affecting Outlook.

  1. CVE-2026-80073Microsoft Office Outlook Information Disclosure Vulnerability6.5
  2. CVE-2026-78519Microsoft Office Outlook Remote Code Execution Vulnerability8.8
  3. CVE-2026-69629Microsoft Office Outlook Remote Code Execution Vulnerability8.8
  4. CVE-2026-62882Microsoft Outlook Spoofing Vulnerability4.3
  5. CVE-2026-70329Microsoft Outlook Remote Code Execution Vulnerability8.8
  6. CVE-2026-42893Microsoft Outlook for iOS Tampering Vulnerability7.4
  7. CVE-2026-26133M365 Copilot Information Disclosure Vulnerability7.1
  8. CVE-2026-21260Microsoft Outlook Spoofing Vulnerability7.5
  9. CVE-2025-49699Microsoft Office Remote Code Execution Vulnerability7.0
  10. CVE-2025-47171Microsoft Outlook Remote Code Execution Vulnerability6.7
  11. CVE-2025-29805Outlook for Android Information Disclosure Vulnerability7.5
  12. CVE-2025-21259Microsoft Outlook Spoofing Vulnerability5.3
  13. CVE-2025-21361Microsoft Outlook Remote Code Execution Vulnerability7.8
  14. CVE-2025-21357Microsoft Outlook Remote Code Execution Vulnerability6.7
  15. CVE-2024-42220A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious ap...7.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store