One of the most significant vulnerabilities fixed in Microsoft's recent Patch Tuesday has already caught the attention of the cybersecurity community, as it concerns Outlook and could allow remote code execution without any action from the victim. The vulnerability, recorded as CVE-2026-40361, is considered particularly dangerous for businesses, organizations, and government agencies that rely on the Microsoft ecosystem every day for communication and email management.

Microsoft describes the issue as a “remote code execution vulnerability” related to Word, but the real impact appears to extend deeper into Outlook, specifically the email rendering engine. The vulnerability was discovered by cybersecurity researcher Haifei Li, creator of the zero-day detection system Expmon, who publicly warned that it was a threat that businesses should not ignore.
See also: Claude Mythos finds only one vulnerability in Curl – what is it?
Zero-click attack without opening attachments
What makes the vulnerability extremely dangerous is the fact that it falls into the category of so-called zero-click vulnerabilities. Simply put, the user does not need to click on a link, download a file, or open an attachment for the attack to be triggered.
According to Li, the vulnerability can be triggered simply by previewing a malicious email in Outlook. The issue is located in a DLL file used by both Microsoft Word and Outlook, allowing an attacker to remotely execute malicious code on a victim's system.
This particular category of attacks is considered one of the most dangerous in the field of cybersecurity, as it bypasses the basic human defense: the user's suspicion. Unlike traditional phishing attacks, here the victim can be compromised without realizing anything.
Outlook vulnerability: The risk for businesses and senior executives
Haifei Li described the vulnerability as a potential "business killer," drawing a direct comparison to the older CVE-2015-6172 vulnerability , known as BadWinmail , which caused huge concern more than a decade ago.
See also: SAP fixes vulnerabilities in Commerce Cloud and S/4HANA
As the researcher explained, the new flaw uses almost the same attack vector and could theoretically allow high-ranking executives, such as CEOs and CFOs, to be compromised simply by sending an email.
The threat becomes even more serious in corporate environments where Outlook and Exchange Server are key communication tools. In such infrastructures, a successful exploit could be used as an initial entry point for ransomware attacks, corporate data theft , or lateral movement within an organization's network.
Experts point out that cybercriminal groups are increasingly targeting high-ranking business executives, as their accounts offer access to sensitive financial data, internal communications and critical corporate decisions.

It is difficult to defend against such attacks
Another concern is that zero-click attacks in Outlook are extremely difficult to mitigate through traditional security solutions. Because the exploitation occurs through Outlook's email rendering engine itself, many corporate defenses, such as firewalls or phishing detection systems, may not be sufficient.
Li noted that one of the few effective ways to mitigate the risk is to configure Outlook to display emails in plain text only. However, this practice is considered difficult to implement in large enterprise environments, as it affects the user experience and functionality of emails.
Microsoft has classified the vulnerability as "exploitation more likely," which usually means that the company considers it quite likely that functional exploits will be created in the near future.
Is there already an exploit?
Although Li said he only developed proof-of-concept (PoC) code and not a fully functional exploit, he made it clear that creating a true weaponized exploit should not be considered impossible.
See also: All the new features that iOS 26.5 brings
In fact, many experts estimate that cybercriminal groups or state-backed attackers will likely already be trying to analyze Microsoft's patch to identify the exact mechanism of the vulnerability.
This process, known as patch diffing, is common practice after major security updates and often leads to the creation of exploits within days of the patches being released.

The need to install updates immediately
CVE-2026-40361 is yet another reminder that email platforms remain one of the most important targets for cyberattacks worldwide. With Outlook used by hundreds of millions of users and businesses, even a single zero-click flaw can become a massive threat.
Cybersecurity experts recommend that businesses immediately install the latest Microsoft security updates, review email protection policies, and strengthen suspicious activity.
In an era where cyberattacks are becoming increasingly sophisticated, zero-click vulnerabilities like this one in Outlook prove that even simply receiving an email can now pose a serious risk to entire businesses and organizations.
