Microsoft Outlook security vulnerability has been flagged as a high-risk issue by India’s cybersecurity agency CERT-In. The flaw could allow a remote attacker to execute arbitrary code on an affected computer.
CERT-In has registered the issue as CVE-2026-70125 and described it as a high-risk remote code execution vulnerability. The problem is linked to improper input verification in Microsoft Outlook.
According to the advisory, an attacker could exploit the flaw by sending a specially crafted payload to a targeted system. If the attack succeeds, the attacker may be able to run arbitrary code on the affected computer.
The potential impact makes the issue important for both organisations and individual users who rely on affected Microsoft products for office or personal work.
Microsoft Outlook Security Vulnerability Affects These Users
According to CERT-In, the affected software includes Microsoft 365 Apps for Enterprise in both 32-bit and 64-bit versions.
Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024 are also listed among the affected software versions, covering both 32-bit and 64-bit editions.
Users running Outlook through these Microsoft packages on office or home computers should check whether security updates are available for their systems.
How the Security Flaw Can Be Exploited
The vulnerability can be targeted remotely through a specially crafted payload. This makes the issue different from an ordinary unwanted email because successful exploitation could give an attacker the ability to execute arbitrary code.
Arbitrary code execution can potentially allow actions beyond the normal use of Outlook and may compromise the affected computer and the data stored on it.
CERT-In has therefore classified the vulnerability as High risk and highlighted the possibility of system compromise following successful exploitation.
What Outlook Users Should Do
CERT-In has advised affected users and organisations to apply the available security updates. Microsoft has released security updates addressing the vulnerability.
Users should check the update settings for Microsoft Office or Microsoft 365 and install available security patches. Keeping the software updated is an important step in reducing exposure to known security flaws.
Users should also remain cautious when handling unexpected emails, suspicious attachments and unfamiliar links, particularly when using Outlook for work or personal communication.
Why Keeping Microsoft Software Updated Matters
Microsoft Outlook security vulnerability highlights why security updates should not be ignored. Older or unpatched software can remain exposed to known vulnerabilities even when users follow normal computer-security practices.
For users of the affected Microsoft products, installing the available security updates is the key action highlighted by CERT-In.


