SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-21509

Microsoft Office Security Feature Bypass Vulnerability

KEVHIGH 7.8EPSS 72.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 16 February 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
72.55% probability · 99th percentile
CISA KEV
Listed 26 January 2026 · due 16 February 2026
Weakness
CWE-807
Affected
microsoft/365 apps · microsoft/office · microsoft/office long term servicing channel
Source
secure@microsoft.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Please adhere to Microsoft’s recommended guidelines to address this vulnerability. Implement all final mitigations provided by the vendor for Office 2021, and apply the interim corresponding mitigations for Office 2016 and Office 2019 until the final patch becomes available. For more information please see: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21509

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.