What happened

CSA Singapore’s June 2026 Monthly Patch highlighted Microsoft Outlook and Word remote code execution vulnerabilities. The advisory rated them highly enough to land in a monthly patch bulletin, which means they deserve attention from any organization that depends on Microsoft productivity software.

Why it matters

Office vulnerabilities are attractive because they sit in everyday workflows. A flaw in Outlook or Word can become a delivery path for malicious content, especially when users open files or messages without thinking twice.

What readers should do

Patch Office software promptly and review email safety practices. If a product appears in a monthly patch bulletin, do not wait for proof of exploitation before acting.

Affected CVEs & remediation checklist

The bulletin covers three Microsoft Outlook/Word remote code execution flaws: CVE-2026-47635, CVE-2026-45458, and CVE-2026-45456, each rated CVSS 8.4. Microsoft's advisory does not specify which product builds remain vulnerable pre-patch, so treat every unpatched Outlook/Word installation as exposed until updated.

Bottom line

User-facing software is still one of the easiest ways for attackers to reach enterprise systems.