logo

Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks

ID: 8dcdcf4a-6b67-5ebe-bdf5-9b7682a13455

STIX ID: report--8dcdcf4a-6b67-5ebe-bdf5-9b7682a13455

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Microsoft released out-of-band patches on 2026-01-26 for CVE-2026-21509, a Microsoft Office zero-day (CVSS 7.8) that allows security-feature bypass of OLE/COM mitigations via untrusted inputs and is confirmed as being actively exploited; affected Office versions include 2016, 2019, LTSC and M365 Apps with patches or service-side protections available, and recommended mitigations are to apply updates immediately, enable auto-updates, consider the registry compatibility-flag workaround, monitor for phishing Office attachments, and deploy EDR to detect COM/OLE anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.