logo

Use Microsoft Office? Hackers can infect your PC with a malicious document - patch it ASAP

ID: 2bbc2088-8ba9-51b3-9dc3-a4ddfb97b03c

STIX ID: report--2bbc2088-8ba9-51b3-9dc3-a4ddfb97b03c

Feed Name: ZDNet Security

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-26

...
...

Microsoft issued an emergency patch for a zero-day Office Security Feature Bypass (CVE-2026-21509) that circumvents OLE mitigations, allowing attackers to deliver malicious document attachments and infect systems; the flaw has been observed in the wild, affects multiple Office/Microsoft 365 versions (including Office 2016, 2019, LTSC and Microsoft 365 Apps), and requires manual updates for older Office releases while newer editions receive a server-side fix and restart.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.