
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21511 is a deserialization of untrusted data vulnerability in Microsoft Office Outlook that allows an unauthenticated remote attacker to perform spoofing over a network. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security update. Affected products include Microsoft Outlook, Word 2016, Office 2019/2021/2024, Microsoft 365 Apps for Enterprise (x86/x64), Office Long-Term Servicing Channel (2021 and 2024 for Windows and macOS), and SharePoint Server 2016, 2019, and Subscription Edition (prior to version 16.0.19127.20518). The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, Feedly).
The root cause is improper deserialization of untrusted data (CWE-502) within Microsoft Office Outlook's network-facing processing logic. An attacker can exploit this flaw over the network without requiring authentication or user interaction, making it a zero-click, network-accessible attack vector. The vulnerability enables spoofing of email messages or sender identity, likely by crafting malicious serialized data that Outlook processes during normal email handling. Emerging Threats published detection rules for this CVE, and Stamus Networks documented network-level detection approaches (Emerging Threats, Stamus Networks).
Successful exploitation allows an unauthenticated attacker to spoof email messages or sender identity in Microsoft Office Outlook over a network, with a high confidentiality impact and no availability or integrity impact per the CVSS scoring. The spoofing capability has been reported as actively leveraged in phishing campaigns designed to steal user credentials, potentially enabling downstream account compromise and lateral movement within enterprise environments. The broad scope of affected products — spanning multiple Office versions, Microsoft 365 Apps, and SharePoint Server — significantly widens the attack surface across both Windows and macOS platforms (Microsoft MSRC, Feedly).
Microsoft released a security update on February 10, 2026 (Patch Tuesday) addressing CVE-2026-21511 across all affected products. Organizations should immediately apply the February 2026 cumulative update to all installations of Microsoft Outlook, Office 2016/2019/2021/2024, Microsoft 365 Apps for Enterprise, Office LTSC 2021/2024 (Windows and macOS), and SharePoint Server (targeting version 16.0.19127.20518 or later for Subscription Edition). As supplementary controls, implement email security gateways with anti-spoofing capabilities (SPF, DKIM, DMARC enforcement), deploy network detection rules from Emerging Threats, and conduct user awareness training to help identify spoofed messages (Microsoft MSRC, Tenable).
The February 2026 Patch Tuesday was widely covered by security vendors and researchers, with Tenable, Qualys, Rapid7, Sophos, and BleepingComputer all publishing analyses of the update cycle that included CVE-2026-21511 (Tenable, BleepingComputer, Sophos). Stamus Networks published a dedicated blog post on detecting attacks targeting CVE-2026-21511 using network detection and response tools (Stamus Networks). The broader February 2026 Patch Tuesday — which addressed 58 flaws including 6 zero-days — received significant attention from the security community, with CVE-2026-21511 noted for its zero-click, unauthenticated exploitation potential in enterprise email environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."