Microsoft Issues Emergency Patch for Active Office Zero-Day
ID: 0b813eb7-14df-5371-9314-4d9225b4ec3c
STIX ID: report--0b813eb7-14df-5371-9314-4d9225b4ec3c
Feed Name: TechRepublic Security
**Microsoft issued emergency out-of-band updates for CVE-2026-21509**, a zero-day in Office that allows attackers to bypass Object Linking and Embedding (OLE) security checks and execute code when users open crafted documents (often delivered via phishing). Microsoft reports active exploitation in the wild and assigned a CVSS score of 7.8; the article recommends immediate patching, registry mitigations where updates cannot be applied, enforcing Protected View/Mark of the Web, applying attack-surface reductions, monitoring with EDR, and testing incident response and backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
