Office Preview Pane RCE: 12 zero-click bugs, patch now
Microsoft's September 2026 Patch Tuesday shipped ~970 CVEs. Twelve Critical Office RCEs fire from the Outlook Reading Pane with no click. Here's the triage order.
Most of Microsoft's September release can wait for your normal change window. A dozen of them cannot, because they execute code when a crafted email lands in the Outlook Reading Pane — no click, no attachment opened, no macro prompt. If your team runs Outlook with the preview pane on, which is the default, that is a zero-click remote code execution path sitting in every inbox you own.
What actually happened
September 2026 was the largest Patch Tuesday on record. Vendor counts differ slightly depending on what they fold in: Tenable counted 964 CVEs with 104 Critical, CrowdStrike counted 972 with 113 Critical, and Ivanti logged 973. Call it roughly 970. Elevation of privilege made up about 45% of the batch; remote code execution about 27%.
Two were already under active exploitation at release, both privilege escalation: CVE-2026-81963 in the Windows Update Stack (link-resolution flaw, low-privilege local user to SYSTEM) and CVE-2026-85880 in Windows ALPC (heap overflow that escapes a low-privilege AppContainer sandbox to SYSTEM). Both carry CVSS 7.8.
The part that should change your weekend is the Office cluster. CrowdStrike's analysis counted 22 Critical Office patches, 12 of which trigger through the Outlook Reading Pane or Explorer Preview Pane. Three of those sit at CVSS 9.8: CVE-2026-77493 (a double-free in Outlook, fires on viewing the message), CVE-2026-78510 (heap overflow via crafted RTF rendered in the preview pane), and CVE-2026-78509. Delivery vectors across the group include email messages, RTF files, and PowerPoint decks.
Separately, Adobe Commerce CVE-2026-75650 is under active exploitation right now. If you run Magento or Adobe Commerce, that one outranks everything on this list.
Why patch triage matters for your business
Nobody with one sysadmin is deploying 970 patches this week. So the honest question is what you deliberately skip.
The preview-pane bugs break the usual reasoning. Most email-borne risk assumes a human decision point — someone opens the attachment, someone enables content, someone clicks. Security awareness training exists because that checkpoint exists. These remove it. Rendering the message is the exploit. Your best-trained employee and your worst one have the same exposure.
Order of operations, this week:
- Adobe Commerce CVE-2026-75650 if you run a store on it. Actively exploited, and it's your revenue.
- The Office/Outlook cluster, everywhere Outlook runs. This is the zero-click set.
- The two exploited Windows zero-days. They need a foothold first, which buys you a little time, but not much.
- Everything internet-facing — VPN, mail gateway, CMS, file transfer.
- The remaining ~960 on your normal monthly cadence, without guilt.
If Outlook patching will take you more than 48 hours, turn off the Reading Pane as a stopgap. It is an ugly mitigation and your team will complain. It also closes the no-click path until the update lands.
Key takeaways
- September 2026 Patch Tuesday was the largest ever — roughly 970 CVEs depending on whose count you use, with 104–119 rated Critical
- 12 Critical Office RCEs execute from the Outlook Reading Pane or Explorer Preview Pane with no user click; three are CVSS 9.8
- Two actively exploited Windows privilege-escalation zero-days: CVE-2026-81963 and CVE-2026-85880, both CVSS 7.8
- Adobe Commerce CVE-2026-75650 is under active exploitation and outranks the Microsoft set if you run a store on it
- Zero-click bugs defeat security awareness training — disabling the Reading Pane is a valid stopgap until you patch
You can't triage what you can't see. We build asset and version inventories that answer "which machines run which Office build, and which are internet-facing" from a single query — so a 970-CVE month becomes a twenty-minute decision instead of a lost weekend. See how we build operational tooling or send us your stack and we'll map the exposure.
Sources: Tenable, CrowdStrike, Zero Day Initiative.
- #patching
- #outlook
- #microsoft
- #security
- #vulnerability-management
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
SGLang CVE-2026-86793: unauthenticated RCE on your GPU box
SGLang's SafeUnpickler can be bypassed through an unauthenticated endpoint for full RCE. No patch at disclosure. How to close it on a self-hosted inference server.
Read itAn AI agent swarm took 440 PaperCut servers
GreyNoise traced hundreds of AI agents compromising 440 PaperCut servers at 395 organizations in 48 countries. First RCE in under four hours. What it changes.
Read it