Microsoft releases update to address zero-day vulnerability in Microsoft Office
ID: 40855fdd-a4c4-590e-8a79-e9cce9e91039
STIX ID: report--40855fdd-a4c4-590e-8a79-e9cce9e91039
Feed Name: Cisco Talos
Threat Score
Microsoft released out-of-band updates in January 2026 to address CVE-2026-21509, a security feature bypass in Microsoft Office (CVSS 7.8) that has been reportedly exploited in the wild and added to CISA's Known Exploited Vulnerabilities list; Microsoft published mitigations and Talos released Snort rules and a ClamAV signature to detect exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
