The Indian Computer Emergency Response Team classified a Microsoft Outlook remote-code flaw as high severity in a 28 September vulnerability note, telling organisations running Microsoft 365 Apps for Enterprise and Office LTSC 2021 or 2024 to patch before spear-phishing crews weaponise the bug.
Technical scope
The issue, tracked as CVE-2026-70125, stems from how Outlook parses specially crafted messages or attachments. CERT-In said successful exploitation could let an attacker execute arbitrary code on the targeted system, a pathway ransomware groups favor in Indian manufacturing and logistics networks that still rely on desktop Office rather than browser clients.
Both 32-bit and 64-bit builds are affected. Microsoft's September cumulative updates contain the fix; CERT-In's note mirrors the vendor rating rather than adding India-specific mitigations, which places the burden on internal IT teams to confirm deployment via patch management consoles.
Why Indian desks should move now
Security researchers documenting income-tax-themed phishing this month showed attackers pairing fake court notices with disk images—a reminder that email remains the breach vector of choice ahead of the 31 July assessment filing season's digital tail. An unpatched Outlook client gives operators a second stage after a user opens a benign-looking message.
Small and medium enterprises often defer Office upgrades until year-end maintenance windows. CERT-In's high rating is meant to break that habit. Managed service providers told InfoHandle Network that several clients still run LTSC 2021 without September's roll-up because of compatibility holds on legacy add-ins.
Operational checklist
Chief information security officers should verify update compliance per business unit, isolate any host that cannot patch immediately, and enable Microsoft Defender attack surface reduction rules where licenses allow. User awareness briefings should stress that government notices arriving via free webmail domains remain fraudulent regardless of patch status.
Until telemetry shows near-universal adoption, CERT-In is likely to keep the note on its active dashboard—a signal for regulated sectors that audit trails must document exception approvals for any remaining vulnerable builds.
Sector exposure
Manufacturing joint ventures that share mailbox access between Indian plants and overseas HQs are particularly exposed, because forwarded .msg files bypass some cloud filters. Legal firms handling merger diligence also use desktop Outlook for redlined attachments—a workflow IT teams struggle to migrate.
State-owned enterprises with air-gapped segments may believe they are isolated, yet any sync with internet-facing mail gateways reintroduces risk. CERT-In's note should trigger exception reporting to boards under SEBI's cyber disclosure norms for listed entities.
Patch verification
Security teams should sample endpoints with vulnerability scanners after patch Tuesday, not rely on update consoles alone. Red-team exercises in banking have shown that one missed laptop in a branch network can become the lateral movement point attackers use to reach core banking VLANs.
