Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Outlook blocks MSIX attachments in web and Windows client

Security Tool/Service
First reported
Last updated
Happening score
H score 14
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft is adding .msix and .msixbundle to the blocked-attachment list in Outlook on the web and new Outlook for Windows, reducing a file-delivery path that attackers have used for unsafe attachments. The change rolls out to Exchange Online users in early November and reaches general availability by mid-November.

Related Happenings

Microsoft Exchange Server weak authorization privilege escalation (CVE-2026-96940)

Vulnerability
H score29 First: 05.10.2026 19:21 Last: 05.10.2026 19:21 Sources 1

About this happening: A weak authorization flaw in Microsoft Exchange Server (CVE-2026-96940) lets an authenticated attacker elevate privileges and read other users' mailboxes withi...

Microsoft Teams expands Weaponizable File Protection with custom blocked-file controls

Security Tool/Service
H score11 First: 18.09.2026 16:58 Last: 18.09.2026 16:58 Sources 1

About this happening: Microsoft Teams is expanding Weaponizable File Protection admin controls so organizations can customize which file types are blocked, reducing exposure to risky attach...

Classic Outlook for Windows Copilot button disappearance and Kaspersky-linked crash issue

Service Disruption
H score0 First: 16.09.2026 15:16 Last: 16.09.2026 15:16 Sources 1

About this happening: Microsoft is still investigating a Classic Outlook for Windows disruption that makes Copilot and Copilot Chat entry points disappear for some Windows users, with t...

Microsoft security patch release for CVE-2026-62911

Security Patch Release
H score32 First: 01.09.2026 15:38 Last: 01.09.2026 15:38 Sources 1

About this happening: Microsoft patched CVE-2026-62911 in Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) during the August 2026 Patch Tu...

Microsoft Exchange Server 2016/2019/SE authentication bypass (CVE-2026-62911)

Vulnerability
H score29 First: 01.09.2026 15:38 Last: 01.09.2026 15:38 Sources 1

About this happening: An authentication bypass in Microsoft Exchange Server 2016/2019/SE leaves about 21,899 exposed servers at risk of mailbox takeover. The flaw is tracked as CVE-2026-6...

Timeline

  1. 07.10.2026 18:44 2 articles · 2h ago

    Microsoft adds .msix and .msixbundle to Outlook attachment blocks

    Initial Disclosure

    Microsoft will add .msix and .msixbundle to the BlockedFileTypes list in OWA Mailbox policies for Outlook on the web and the new Outlook for Windows, starting with an Exchange Online rollout in early November and reaching general availability by mid-November. After the policy update, users of Outlook on the web and new Outlook for Windows will not be able to send, receive, open, or download those attachments by default, and administrators can whitelist them through AllowedFileTypes if business needs require it.

    Show sources