logo

Microsoft patches actively exploited Office zero-day vulnerability

ID: 315afc36-d594-5fbe-8eb5-6103d469b346

STIX ID: report--315afc36-d594-5fbe-8eb5-6103d469b346

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2026-01-26

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft issued emergency out-of-band updates and mitigation guidance for CVE-2026-21509, a high-severity Microsoft Office zero-day being actively exploited to bypass OLE/COM mitigations; affected products include Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps, with registry-based mitigations provided and patches pending for some older versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.