CVE-2026-21260

Severity
7.5HIGH
EPSS
0.0%
top 85.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10

Description

Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages12 packages

CVEListV5microsoft/microsoft_office_201919.0.0https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_outlook_201616.0.0.016.0.5539.1002
CVEListV5microsoft/microsoft_office_ltsc_202116.0.1https://aka.ms/OfficeSecurityReleases
CVEListV5microsoft/microsoft_office_ltsc_202416.0.0https://aka.ms/OfficeSecurityReleases

🔴Vulnerability Details

2
GHSA
GHSA-2pm9-6ww9-wqv9: Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a netw2026-02-10
CVEList
Microsoft Outlook Spoofing Vulnerability2026-02-10

📋Vendor Advisories

1
Microsoft
Microsoft Outlook Spoofing Vulnerability2026-02-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-21260 Impact, Exploitability, and Mitigation Steps | Wiz