logo

CVE-2026-21509: APT28 Exploits Microsoft Office Zero-day Vulnerability

ID: cf44c001-9e00-5acb-a26e-0f6f5b3de1b3

STIX ID: report--cf44c001-9e00-5acb-a26e-0f6f5b3de1b3

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2026-02-04

Date Updated: 2026-07-22

Author: Huseyin Can YUCEEL

...
...

Microsoft disclosed CVE-2026-21509, a critical RTF-parsing zero-day in Office (CVSS 7.8) that allows remote code execution; APT28 (Fancy Bear) exploited it in January 2026 in Operation Neusploit against Ukrainian targets, delivering payloads such as MiniDoor, PixyNetLoader, and a Covenant-based backdoor to achieve persistence, data theft, and remote control. The report outlines the exploitation chain, affected products and versions, persistence and C2 behaviors, mitigation guidance, and offers security validation simulation via the Picus platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.