Under Attack: Microsoft Patches Office Zero-Day (CVE-2026-21509) Exploited in the Wild
ID: 833807b7-ce17-526d-80d2-a12317e06eb3
STIX ID: report--833807b7-ce17-526d-80d2-a12317e06eb3
Feed Name: securityonline.info
Threat Score
Microsoft disclosed and patched CVE-2026-21509, a CVSS 7.8 security-feature-bypass vulnerability in Office’s OLE/COM handling that has been exploited in the wild. Exploitation requires user interaction (opening a malicious Office file) and bypasses OLE mitigations; Microsoft released fixes on 2026-01-26 for Office 2016 and 2019 and documented a registry-based workaround for environments that cannot immediately apply the update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
