CVE-2026-21509

9.5 CISA KEV

Microsoft · Office

A security feature bypass vulnerability in Microsoft Office allows an unauthorized attacker to manipulate security decisions via untrusted inputs.

Executive summary

This critical security feature bypass vulnerability in Microsoft Office is currently being actively exploited in the wild, posing an immediate risk of system compromise.

Vulnerability

The flaw stems from a reliance on untrusted inputs during security decision-making processes (CWE-807). An attacker can trigger this vulnerability locally to bypass critical security features, which may lead to total system impact.

Business impact

The exploitation of this vulnerability allows for unauthorized actions that can lead to a complete loss of confidentiality, integrity, and availability. Given the CVSS score of 9.5 and the confirmed active exploitation, this represents a severe threat to organizational security, potentially facilitating unauthorized code execution or lateral movement within the environment.

Remediation

Immediate Action: Apply the vendor-supplied security updates immediately by following the guidance provided at the official Microsoft Security Update Guide.

Proactive Monitoring: Review endpoint security logs for suspicious Office application behavior, specifically focusing on unauthorized file modifications or unexpected process execution chains.

Compensating Controls: Ensure that macro security settings are strictly enforced and that users are trained to exercise caution when opening untrusted Office documents until patches are deployed.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept are available on GitHub.

Analyst recommendation

Due to the critical nature of this vulnerability and the evidence of active exploitation, this issue must be prioritized for immediate remediation. Organizations should deploy the relevant security updates provided by Microsoft across all affected Office versions without delay to neutralize the risk of bypass and subsequent system exploitation.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Analyst report written
  23. Fix documented version 16.0.5539.1001 per CVE record

Sources