logo

CVE-2026-21509: Actively Exploited Microsoft Office Zero-Day Forces Emergency Patch

ID: 479d364b-a5b4-5792-b3df-fffa7a6c8fd8

STIX ID: report--479d364b-a5b4-5792-b3df-fffa7a6c8fd8

Feed Name: SOC Prime Blog

Threat Score
80/100

Date Published: 2026-01-27

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

This report details CVE-2026-21509, a Microsoft Office security-feature-bypass zero-day actively exploited in the wild; Microsoft issued an out-of-band update and the vulnerability was added to CISA's KEV catalog, requiring federal agencies to patch. Affected products include Office 2016, 2019, LTSC 2021/2024 and Microsoft 365 Apps for Enterprise; mitigations include an automatic service-side fix for Office 2021+, updates or a registry-based workaround for older versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.