CVE-2023-35636Medium· 6.5▾ TwilightPoC availableMicrosoft Outlook Information Disclosure Vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 3.5 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
18%
1 GitHub repo (last check)
Microsoft Outlook Information Disclosure Vulnerability
365_appsoffice = 2016office = 2019office_long_term_servicing_channel = 2021Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70125High· 8.8Microsoft Office Outlook Remote Code Execution Vulnerability
CVE-2026-85875Medium· 5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-83951Medium· 5.5Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-81397High· 7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81398High· 7.8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81399Medium· 5.5Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.