CVE-2026-21260
vulnerability analysis and mitigation

Overview

CVE-2026-21260 is an information disclosure vulnerability in Microsoft Office Outlook that enables unauthorized attackers to perform email spoofing attacks over a network. Classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), it affects Microsoft Outlook 2016, Office 2019, 2021, and 2024, Microsoft 365 Apps for Enterprise, Office Long-Term Servicing Channel 2021 and 2024, and SharePoint Server 2016 and 2019. The vulnerability was publicly disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday release. It carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is improper exposure of sensitive information (CWE-200) within Microsoft Office Outlook's handling of network communications, which can be leveraged by an unauthenticated remote attacker to conduct spoofing attacks. The attack vector is network-based, requires no privileges and no user interaction, and has low attack complexity, making it straightforward to exploit remotely. The specific mechanism by which sensitive information is exposed to enable spoofing has not been publicly detailed in available technical write-ups, and no public proof-of-concept code has been identified (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in a high confidentiality impact with no integrity or availability impact, as the vulnerability enables an attacker to expose sensitive information and use it to impersonate trusted email senders. This spoofing capability could be weaponized to conduct large-scale phishing campaigns or credential theft operations by sending emails that appear to originate from legitimate sources. The broad scope of affected products — spanning multiple Office versions and SharePoint Server — means a significant portion of enterprise environments could be at risk (Microsoft MSRC, Feedly).

Mitigation and workarounds

Microsoft released security updates addressing CVE-2026-21260 on February 10, 2026, as part of the February 2026 Patch Tuesday. Affected products requiring patching include Microsoft Outlook 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise (x86 and x64), Office Long-Term Servicing Channel 2021 and 2024, and SharePoint Server 2016, 2019, and Subscription Edition (versions prior to 16.0.19127.20518). Organizations should apply the relevant security updates immediately via Windows Update, Microsoft Update Catalog, or their patch management solution, prioritizing Outlook and Office installations given the high confidentiality impact and ease of network exploitation (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader February 2026 Patch Tuesday reporting by multiple security outlets including BleepingComputer, Qualys, Rapid7, and Sophos, though CVE-2026-21260 was not highlighted as one of the more critical or zero-day vulnerabilities in that release cycle. Security researchers noted the spoofing risk in the context of phishing enablement, but the vulnerability did not generate significant standalone commentary given the absence of active exploitation or a public PoC (BleepingComputer, Qualys Blog, Rapid7).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management