ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft reveals actively exploited Office zero-day, provides emergency fix (CVE-2026-21509)

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-21509

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21509
Local Security Feature Bypass in Microsoft Office Under Active Exploitation

CVE-2026-21509 is a security feature bypass in Microsoft Office caused by reliance on untrusted input when making a security decision (CWE-807): Office trusts attacker-controlled data when deciding whether a protection applies, allowing an unauthorized local attacker to bypass that security feature. Exploitation is local and requires user interaction (per the CVSS vector), most plausibly by getting a user to open a crafted file or document, and the flaw carries high confidentiality, integrity, and availability impact. Anyone running Microsoft Office, Microsoft 365 Apps, or Office Long Term Servicing Channel is in scope, giving the flaw a potential audience in the hundreds of millions of seats. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-26, Microsoft issued an emergency patch, and headlines attribute in-the-wild use to Russian state hackers targeting Ukrainian and EU organizations, including the maritime and transport sectors (a related APT28 campaign was tied to a separate Office/MSHTML 0-day, CVE-2026-21513). EPSS estimates a 72.6% probability of exploitation within the next 30 days (99th percentile).

Do: Apply Microsoft's emergency Office update and the follow-on February 2026 Patch Tuesday fixes across Microsoft 365 Apps, Office, and Office LTSC, checking Microsoft's advisory for the exact affected builds since no version ranges are given in the source data. Given the KEV listing, federal agencies must patch per CISA BOD 22-01 timelines (or follow cloud-service guidance). Hunt for exploitation per vendor guidance — headlines report Russian state use against EU/Ukrainian and maritime/transport targets — and prioritize endpoints where users open untrusted files.

7.873% KEV
  • Microsoft Office
  • Microsoft 365 Apps
  • Microsoft Office Long Term Servicing Channel (LTSC)
masshundreds of millions of users/devices (Office and Microsoft 365 Apps have a global installed base on the order of 10^8+ seats)
Full article397 words · extracted from helpnetsecurity.com · click to collapse

Microsoft released emergency Office security updates to fix a security feature bypass vulnerability (CVE-2026-21509) that its threat intelligence and security teams spotted being exploited in the wild in zero-day attacks.

Users and admins are advised to review the associated advisory and to implement updates or mitigations as soon as possible.

About CVE-2026-21509

CVE-2026-21509 stems from reliance on untrusted inputs in a security decision in Microsoft Office, which allows unauthorized attackers to bypass a security feature (OLE mitigations in Microsoft 365 and Microsoft Office) locally.

“The Preview Pane is not an attack vector. An attacker must send a user a malicious Office file and convince them to open it,” Microsoft noted. Successful exploitation thus hinges on user interaction, but tricking users into opening Office files has never been an insurmountable problem for attackers.

Microsoft detected exploitation of the flaw in the wild. The good news is that a PoC exploit for it is not currently publicly available, which probably means that the exploit is wielded by a limited number of threat actors against specific targets (as opposed to against the entirety of Office users).

Microsoft’s Threat Intelligence Center (MSTIC), Security Response Center (MSRC), and Office Product Group Security Team have been credited with flagging the vulnerability. The company hasn’t shared additional details of the attacks or publicly identified possible targets.

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-21509 to its Known Exploited Vulnerabilities catalog and ordered US federal civilian agency to address the flaw by February 16, 2026.

Security updates

While Microsoft initially only released updates for Office 2021 and later, it didn’t take long for them to make them available for icrosoft Office 2016 and 2019 users.

“Customers running Office 2021 and later will be automatically protected via a service-side change, but will be required to restart their Office applications for this to take effect,” Microsoft explained.

“Customers running Microsoft Office 2016 and 2019 should ensure the update is installed to be protected from this vulnerability.”

Alternatively, those who are comfortable with making changes to the Windows registry can add a specific registry subkey (as detailed in Microsoft’s advisory) to protect themselves against exploitation.

UPDATE (February 3, 2026, 01:40 p.m. ET):

Zscaler and Ukraine’s CERT have spotted Russian state-sponsored APT Fancy Bear exploiting the vulnerability.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/01/27/microsoft-reveals-actively-exploited-office-zero-day-provides-emergency-fix-cve-2026-21509/