ThreatCluster

Critical RCE Vulnerabilities Found in Microsoft Outlook and Word

1d ago CybersecuritynewsGbhackers 93% similarity 72
Share:

Article Content

Browse articles
ThreatCluster

Microsoft has disclosed three critical remote code execution (RCE) vulnerabilities in Outlook and Word, identified as CVE-2026-45456, CVE-2026-45458, and CVE-2026-47635. These vulnerabilities, published on June 9, 2026, are linked to low-level memory safety issues in the Word rendering engine and its integration with Outlook Classic. Attackers could exploit these flaws to execute arbitrary code on targeted systems, affecting users of both applications. The vulnerabilities have a CVSS v3.1 base score of 8.4, indicating a high severity level. Microsoft has released patches to address these vulnerabilities, and users are urged to update their software immediately to mitigate potential risks. Security researchers are monitoring the situation for any signs of active exploitation.

Key Points: • Three critical RCE vulnerabilities in Microsoft Outlook and Word disclosed on June 9, 2026. • Vulnerabilities allow attackers to execute arbitrary code on affected systems. • Patches are available, and users are advised to update their software immediately.

ThreatCluster AI

Timeline

2026-06-09
CVE-2026-45456 published
Microsoft disclosed a critical RCE vulnerability in Outlook and Word, allowing arbitrary code execution.
Gbhackers
2026-06-09
CVE-2026-45458 published
Another critical RCE vulnerability was disclosed, related to the Word rendering engine.
Gbhackers
2026-06-09
CVE-2026-47635 published
A third critical RCE vulnerability affecting Outlook and Word was made public.
Gbhackers
2026-06-12
Patches released
Microsoft released critical fixes for the vulnerabilities, urging users to update their software.
Cybersecuritynews

Community

Browse all →