What happened
CSA Singapore’s June 2026 Monthly Patch highlighted Microsoft Outlook and Word remote code execution vulnerabilities. The advisory rated them highly enough to land in a monthly patch bulletin, which means they deserve attention from any organization that depends on Microsoft productivity software.
Why it matters
Office vulnerabilities are attractive because they sit in everyday workflows. A flaw in Outlook or Word can become a delivery path for malicious content, especially when users open files or messages without thinking twice.
What readers should do
Patch Office software promptly and review email safety practices. If a product appears in a monthly patch bulletin, do not wait for proof of exploitation before acting.
Affected CVEs & remediation checklist
The bulletin covers three Microsoft Outlook/Word remote code execution flaws: CVE-2026-47635, CVE-2026-45458, and CVE-2026-45456, each rated CVSS 8.4. Microsoft's advisory does not specify which product builds remain vulnerable pre-patch, so treat every unpatched Outlook/Word installation as exposed until updated.
- Apply the June 2026 Microsoft security updates via Windows Update or WSUS/Intune as soon as your test cycle allows — don't wait for the next scheduled patch window given the RCE severity.
- Check each CVE individually on Microsoft's Security Update Guide (MSRC) for the specific KB article covering your Office build.
- In the meantime, enable Office's "Protected View" for files from the internet and disable auto-preview of email attachments where feasible.
- Prioritize internet-facing or high-privilege users (finance, HR, executives) for immediate patching.
Bottom line
User-facing software is still one of the easiest ways for attackers to reach enterprise systems.
CYBERSHIELDZONE