Article Details

Scrape Timestamp (UTC): 2026-01-27 07:24:25.778

Source: https://thehackernews.com/2026/01/microsoft-issues-emergency-patch-for.html

Original Article Text

Click to Toggle View

Microsoft Office Zero-Day (CVE-2026-21509) - Emergency Patch Issued for Active Exploitation. Microsoft on Monday issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability exploited in attacks. The vulnerability, tracked as CVE-2026-21509, carries a CVSS score of 7.8 out of 10.0. It has been described as a security feature bypass in Microsoft Office. "Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally," the tech giant said in an advisory. "This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office, which protect users from vulnerable COM/OLE controls." Successful exploitation of the flaw relies on an attacker sending a specially crafted Office file and convincing recipients to open it. It also noted that the Preview Pane is not an attack vector. The Windows maker said customers running Office 2021 and later will be automatically protected via a service-side change, but will be required to restart their Office applications for this to take effect. For those running Office 2016 and 2019, it's required to install the following updates - As mitigation, the company is urging that customers make a Windows Registry change by following the steps outlined below - Microsoft has not shared any details about the nature and the scope of attacks exploiting CVE-2026-21509. It credited the Microsoft Threat Intelligence Center (MSTIC), Microsoft Security Response Center (MSRC), and Office Product Group Security Team for discovering the issue. The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by February 16, 2026.

Daily Brief Summary

VULNERABILITIES // Microsoft Issues Emergency Patch for Office Zero-Day Vulnerability

Microsoft released an out-of-band patch for a critical zero-day vulnerability, CVE-2026-21509, affecting Microsoft Office with a CVSS score of 7.8.

The vulnerability allows attackers to bypass security features in Microsoft Office by exploiting untrusted inputs, posing significant risks if left unpatched.

Exploitation involves sending a specially crafted Office file to users, requiring them to open it, though the Preview Pane is not a vector.

Microsoft automatically protects Office 2021 and later users via a service-side change, necessitating an application restart for full protection.

Users of Office 2016 and 2019 must manually install updates and apply a Windows Registry change as a mitigation measure.

The U.S. CISA has added CVE-2026-21509 to its Known Exploited Vulnerabilities catalog, mandating patch application by February 16, 2026, for federal agencies.

Microsoft's Threat Intelligence Center, Security Response Center, and Office Product Group Security Team were instrumental in identifying and addressing the flaw.