Deserialization Vulnerability in Microsoft Office Outlook
CVE-2026-21511
7.5HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2026-21511?
A deserialization vulnerability in Microsoft Office Outlook enables an attacker to exploit untrusted data, leading to potential network spoofing attacks. This security flaw could allow unauthorized individuals to impersonate legitimate users and intercept communication, posing a significant threat to data integrity and confidentiality.
Affected Version(s)
Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1
Microsoft Office 2019 32-bit Systems 19.0.0
Microsoft Office LTSC 2021 32-bit Systems 16.0.1