CVE-2026-21509
9.5 CISA KEVMicrosoft · Office
A security feature bypass vulnerability in Microsoft Office allows an unauthorized attacker to manipulate security decisions via untrusted inputs.
Executive summary
This critical security feature bypass vulnerability in Microsoft Office is currently being actively exploited in the wild, posing an immediate risk of system compromise.
Vulnerability
The flaw stems from a reliance on untrusted inputs during security decision-making processes (CWE-807). An attacker can trigger this vulnerability locally to bypass critical security features, which may lead to total system impact.
Business impact
The exploitation of this vulnerability allows for unauthorized actions that can lead to a complete loss of confidentiality, integrity, and availability. Given the CVSS score of 9.5 and the confirmed active exploitation, this represents a severe threat to organizational security, potentially facilitating unauthorized code execution or lateral movement within the environment.
Remediation
Immediate Action: Apply the vendor-supplied security updates immediately by following the guidance provided at the official Microsoft Security Update Guide.
Proactive Monitoring: Review endpoint security logs for suspicious Office application behavior, specifically focusing on unauthorized file modifications or unexpected process execution chains.
Compensating Controls: Ensure that macro security settings are strictly enforced and that users are trained to exercise caution when opening untrusted Office documents until patches are deployed.
Exploitation status
Public Exploit Available: Yes, multiple public proofs-of-concept are available on GitHub.
Analyst recommendation
Due to the critical nature of this vulnerability and the evidence of active exploitation, this issue must be prioritized for immediate remediation. Organizations should deploy the relevant security updates provided by Microsoft across all affected Office versions without delay to neutralize the risk of bypass and subsequent system exploitation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written
- Fix documented version 16.0.5539.1001 per CVE record
Sources
- Microsoft Office Security Feature Bypass Vulnerability Vendor advisory