Microsoft released June 2026 security updates that include fixes for three critical remote code execution vulnerabilities in Outlook and Word: CVE-2026-45456, CVE-2026-45458, and CVE-2026-47635. The flaws were described as memory-safety issues in the Word rendering engine, which Outlook Classic uses to render email content, creating a no-click attack path through the Outlook Preview Pane. Microsoft assigned each issue a CVSS score of 8.4 and said no active exploitation had been observed at the time of disclosure.
The vulnerabilities affect supported Microsoft Office and Outlook builds, including Office LTSC 2024, and were addressed as part of Microsoft’s June Patch Tuesday releases highlighted by multiple security advisories. Reporting on the updates urged organizations to prioritize patch deployment, especially for systems running Outlook Classic and Word, and to consider temporary risk reduction measures such as disabling the Preview Pane in high-risk environments while monitoring for suspicious Office-related process activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
At the time of the 2026-06-09 disclosure, Microsoft stated it had not observed active exploitation of CVE-2026-45456, CVE-2026-45458, and CVE-2026-47635. All three vulnerabilities were assigned CVSS v3.1 scores of 8.4.
On 2026-06-09, Microsoft disclosed and patched three critical remote code execution vulnerabilities: CVE-2026-45456, CVE-2026-45458, and CVE-2026-47635. The flaws affect the Word rendering engine used by Outlook Classic, making the Outlook Preview Pane a no-click attack vector.
On 2026-03-10, Microsoft’s March 2026 vulnerability cycle was released, covering 86 CVEs including 10 Critical flaws and two publicly disclosed zero-days. Reported priorities included SQL Server privilege escalation CVE-2026-21262 and Microsoft Authenticator information disclosure CVE-2026-26123.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourcethreathunter.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.