logo

Microsoft Rushes Emergency Patch for Office Zero-Day

ID: c0ad3a35-c4d3-5a54-a91b-4abee6a9da5f

STIX ID: report--c0ad3a35-c4d3-5a54-a91b-4abee6a9da5f

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-01-27

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft issued an emergency patch for a zero-day vulnerability (CVE-2026-21509, CVSS 7.8) in Office and Microsoft 365 that allows bypass of COM/OLE protection and remote code execution; Microsoft observed active exploitation and CISA added the flaw to its Known Exploited Vulnerabilities catalog, while vendors characterize the exploit as complex and likely used in targeted, potentially state-sponsored or espionage-related attacks, and Microsoft and vendors have published mitigations and updates for affected versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.