logo

Microsoft Office zero-day lets malicious documents slip past security checks

ID: 41d6e981-ebf7-56ce-9b86-f1ac78ae3fe6

STIX ID: report--41d6e981-ebf7-56ce-9b86-f1ac78ae3fe6

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-04-28

...
...

Microsoft has issued an emergency patch for a high-severity Microsoft Office Security Feature Bypass zero-day (CVE-2026-21509, CVSS 7.8) that allows attackers to bypass OLE mitigations and execute hidden code in Word/Excel/PowerPoint documents; the flaw is being exploited in the wild and public proof-of-concept code exists. Affected products include Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps; Office 2021+ receives a server-side fix after restarting apps while older builds require a manual Windows Update. Users are advised to apply the patch, avoid opening unsolicited attachments, keep macros disabled, and maintain up-to-date anti-malware and OS/software updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.