Microsoft Releases Patch for Office Zero Day Amid Evidence of Exploitation
ID: 4a2c463a-b4ad-51db-8319-3c2b65acf8d1
STIX ID: report--4a2c463a-b4ad-51db-8319-3c2b65acf8d1
Feed Name: Infosecurity Magazine (News)
Threat Score
Microsoft disclosed a high-severity zero-day (CVE-2026-21509, CVSS 7.8) in Microsoft Office that allows attackers to bypass OLE mitigations for COM/OLE controls. The flaw has been observed exploited in the wild; Microsoft released patches on January 26 and applied service-side protections for newer Office versions while urging users of affected Office 2016/2019 to install updates and restart applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
