S

EPISODE · May 13, 2026 · 0 MIN

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

from Security Stuff · host Trace3

Microsoft has patched a critical zero-click Outlook vulnerability that security researcher Haifei Li calls an "enterprise killer," allowing attackers to execute code simply by sending an email that's read or previewed, with no clicking required. The flaw, tracked as CVE-2026-40361, is a use-after-free bug affecting Outlook's email rendering engine that bypasses firewalls and directly targets executives' inboxes, though developing a full working exploit remains challenging. Li recommends immediate patching and notes that switching Outlook to plain text mode is the only effective mitigation aside from the security update.

Episode metadata supplied by the publisher feed · Published May 13, 2026

Embed this episode

NOW PLAYING

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

0:00 0:44

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security Stuff?

This episode is 0 minutes long.

When was this Security Stuff episode published?

This episode was published on May 13, 2026.

Can I download this Security Stuff episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!