logo

Office zero-day exploited in the wild forces Microsoft OOB patch

ID: 58356be4-b0d1-50b3-8d00-5418ab28c5c2

STIX ID: report--58356be4-b0d1-50b3-8d00-5418ab28c5c2

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-01-27

Date Updated: 2026-04-26

Author: Carly Page

...
...

Microsoft issued an emergency patch for CVE-2026-21509, a CVSS 7.8 security-feature-bypass zero-day in Office that is being exploited in the wild via malicious documents that convince users to open them; the flaw abuses legacy COM/OLE components, affects a wide range of Office versions (with fixes available for newer builds but not yet for Office 2016/2019), and CISA has added it to its Known Exploited Vulnerabilities catalog while Microsoft recommends registry-based mitigations for affected customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.