Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2026-21260


Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.


Published

2026-02-10T18:16:27.947

Last Modified

2026-02-11T19:10:20.090

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft 365_apps - Yes
Application microsoft 365_apps - Yes
Application microsoft office 2019 Yes
Application microsoft office 2019 Yes
Application microsoft office_long_term_servicing_channel 2021 Yes
Application microsoft office_long_term_servicing_channel 2021 Yes
Application microsoft office_long_term_servicing_channel 2024 Yes
Application microsoft office_long_term_servicing_channel 2024 Yes
Application microsoft outlook 2016 Yes
Application microsoft outlook 2016 Yes
Application microsoft sharepoint_server < 16.0.19127.20518 Yes
Application microsoft sharepoint_server 2016 Yes
Application microsoft sharepoint_server 2019 Yes

References