ZeroHour

CVE-2026-21514

KEVmass

Actively Exploited Security Feature Bypass in Microsoft Word (CVE-2026-21514)

CISA: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p74
Published
()
KEV added
AI analysis

CVE-2026-21514 is a security feature bypass in Microsoft Word caused by the application relying on untrusted inputs when making a security decision (CWE-807). The flaw carries a local attack vector with a user-interaction requirement, so it is most plausibly triggered when a user opens attacker-supplied content, such as a crafted document, on a system running Word. A local, unauthorized attacker who exploits it can circumvent a Word security feature, with high-impact confidentiality, integrity, and availability effects on the local system; bypasses of this type are commonly chained with other flaws for deeper compromise. Any organization running Microsoft 365 Apps or Office Long Term Servicing Channel (LTSC) is affected. CISA added the bug to the Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, though no public proof-of-concept is known and EPSS currently estimates a 1.5% chance of exploitation in the next 30 days (73rd percentile).

What to do: Apply the February 2026 Patch Tuesday security updates from Microsoft for Microsoft 365 Apps and Office LTSC immediately; fixed version numbers were not provided in the source data, so use Microsoft's release guidance to confirm builds. Because the flaw is in CISA KEV, federal agencies must satisfy BOD 22-01 by applying the update (or directed mitigations) within the mandated weeks, and all organizations should prioritize endpoints that open untrusted documents. Until patched, consider Office hardening such as marking files from the internet as untrusted in Word and watching for anomalous document-driven local activity.

Affected
Microsoft 365 Apps
Microsoft Office Long Term Servicing Channel (LTSC)
Microsoft Office (broadly listed by CISA)
Estimated exposure
masshundreds of millions of users (Word is bundled in Microsoft 365 and Office across most enterprise desktop fleets) — Exposure is estimated from the deployment scale of Microsoft 365 and Office LTSC, which ship with Word in hundreds of millions of paid seats and virtually all managed Windows estates, rather than from any public internet-exposure scan.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
365 apps, office long term servicing channel
Weakness
CWE-807
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news