logo

Microsoft Issues Emergency Patch for Active Office Zero-Day

ID: 0b813eb7-14df-5371-9314-4d9225b4ec3c

STIX ID: report--0b813eb7-14df-5371-9314-4d9225b4ec3c

Feed Name: TechRepublic Security

Threat Score
80/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

**Microsoft issued emergency out-of-band updates for CVE-2026-21509**, a zero-day in Office that allows attackers to bypass Object Linking and Embedding (OLE) security checks and execute code when users open crafted documents (often delivered via phishing). Microsoft reports active exploitation in the wild and assigned a CVSS score of 7.8; the article recommends immediate patching, registry mitigations where updates cannot be applied, enforcing Protected View/Mark of the Web, applying attack-surface reductions, monitoring with EDR, and testing incident response and backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.