CVE-2026-21260
CVE-2026-21260: 1 tracked advisory record across MS Server. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
MS Server
1 advisory- Advisory severityHigh7.5
High [CVE-2026-21260] Microsoft Outlook Spoofing Vulnerability
CVE-2026-21260Source published Source updated
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
- Affected products in this advisory
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
- Source-reported affected versions
- Microsoft 365 Apps for Enterprise 16.0.1 before https://aka.ms/OfficeSecurityReleases
- Microsoft Office 2019 19.0.0 before https://aka.ms/OfficeSecurityReleases
- Microsoft Office LTSC 2021 16.0.1 before https://aka.ms/OfficeSecurityReleases
- Microsoft Office LTSC 2024 16.0.0 before https://aka.ms/OfficeSecurityReleases
4 more entries in the full advisory.
- Source-reported fixed versions
- https://aka.ms/OfficeSecurityReleases
- 16.0.5539.1002
- 16.0.10417.20097
- 16.0.19127.20518
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future MS Server CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.