Office Zero-Day Exploited, Forces Microsoft OOB Patch
Microsoft patched a high-severity Office zero-day exploited via low-complexity local attacks that bypass OLE mitigations, but updates for Office 2016 and 2019 are pending.
- On Monday, Microsoft disclosed CVE-2026-21509 and released emergency out-of-band updates rolling out for Microsoft 365 Apps for Enterprise and multiple Microsoft Office LTSC and perpetual releases.
- The flaw bypasses Object Linking and Embedding and COM mitigations, enabling attackers to exploit phishing-style, user-interaction attacks with circulating exploit code, Microsoft said.
- Microsoft published Registry mitigation steps to create a COM Compatibility key and set a Compatibility Flags value to 400; Office 2021 and later get auto-protection after restart, but patches for Microsoft Office 2016 and 2019 are pending.
- Close all Microsoft Office applications before editing the Windows Registry, back up the Registry to avoid system issues, and after performing the steps, the flaw is mitigated on next Office launch.
- Earlier this month, as part of the January 2026 Patch Tuesday, Microsoft fixed 114 flaws including an actively exploited Desktop Window Manager zero-day, and last week it issued other out-of-band fixes while declining to name the vulnerability's discoverer.
25 Articles
25 Articles
Fixes released for a serious Microsoft Office zero-day flaw
Microsoft is warning admins of an Office security bypass zero day vulnerability that can be triggered simply by a user opening a document. The flaw is currently being actively exploited. “The vulnerability is serious,” said Johannes Ullrich, dean of research at the SANS Institute. “The root cause is that Microsoft Office still supports the older OLE document format, which provides access to various OLE components. The effect is similar to what a…
Microsoft warns against a critical vulnerability in Office. The gap is already actively exploited, users should act quickly.
Microsoft releases emergency fix for actively exploited Office vulnerability
Microsoft has acknowledged the existence of an actively exploited zero day vulnerability in its Office suite. The company has also released a fix for the flaw, which is tracked as CVE-2026-21509. Described as a “Microsoft Office Security Feature Bypass Vulnerability”, it has been assigned a severity rating of Important. This is in part because of the fact that active exploitation has been observed. In a post to the Microsoft Security Response Ce…
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










