logo

Microsoft Releases Patch for Office Zero Day Amid Evidence of Exploitation

ID: 4a2c463a-b4ad-51db-8319-3c2b65acf8d1

STIX ID: report--4a2c463a-b4ad-51db-8319-3c2b65acf8d1

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-22

...
...

Microsoft disclosed a high-severity zero-day (CVE-2026-21509, CVSS 7.8) in Microsoft Office that allows attackers to bypass OLE mitigations for COM/OLE controls. The flaw has been observed exploited in the wild; Microsoft released patches on January 26 and applied service-side protections for newer Office versions while urging users of affected Office 2016/2019 to install updates and restart applications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.