EIP-2026-118863
PRE-CVEMicrosoft Outlook Express 5/6 - Script Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118863. PoCs published by http-equiv.
AI-analyzed exploit summary This exploit leverages a re-introduced vulnerability in Microsoft Outlook Express, allowing arbitrary JavaScript execution via a malformed MIME email with an `<img>` tag using the `dynsrc` attribute. The PoC demonstrates an XSS-like attack vector through email rendering.
Description
Microsoft Outlook Express 5/6 - Script Execution
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by http-equiv · textremotewindows
https://www.exploit-db.com/exploits/22959
This exploit leverages a re-introduced vulnerability in Microsoft Outlook Express, allowing arbitrary JavaScript execution via a malformed MIME email with an `<img>` tag using the `dynsrc` attribute. The PoC demonstrates an XSS-like attack vector through email rendering.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Microsoft Outlook Express (version unspecified, likely pre-2006)
No auth needed
Prerequisites:
Victim must open the malicious email in a vulnerable version of Outlook Express
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026