
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21509 is a security feature bypass vulnerability in Microsoft Office caused by reliance on untrusted inputs in a security decision (CWE-807). It allows an unauthorized local attacker to bypass Office security protections, requiring user interaction (e.g., opening a malicious document). Affected products include Microsoft Office 2016, 2019, 2021, 2024, Office LTSC 2021/2024, and Microsoft 365 Apps for Enterprise (x86 and x64). Microsoft disclosed and patched the vulnerability on January 26, 2026, via an out-of-band emergency update. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, CISA KEV).
The vulnerability stems from improper validation of untrusted inputs used in security-critical decision-making within Microsoft Office (CWE-807: Reliance on Untrusted Inputs in a Security Decision). Specifically, it abuses the OLE/COM object handling mechanism — sometimes referred to as "breaking the kill bit" — allowing malicious Office documents (including RTF files) to bypass security controls such as Protected View or macro execution restrictions. The attack vector is local with user interaction required: a victim must open a crafted document. Exploitation does not require elevated privileges. Technical analysis by Logpoint and decalage.info revealed that the flaw involves manipulation of OLE-embedded objects to circumvent security enforcement logic (Logpoint, decalage.info, Microsoft MSRC).
Successful exploitation allows an attacker to bypass Office security features, enabling malicious documents to execute code or load payloads that would otherwise be blocked. The confidentiality, integrity, and availability impacts are all rated High, meaning a fully compromised Office session can lead to credential theft, data exfiltration, and malware installation. In observed campaigns, exploitation led to deployment of multiple malware families including LAMEHUG, GONEPOSTAL, BEARDSHELL, MiniDoor backdoor, GRUNT (Covenant C2), PixyNetLoader, ROMCOM RAT, and the Outlook Backdoor, enabling persistent access, email theft, and lateral movement across government and enterprise networks (Trellix, BleepingComputer).
Microsoft released an out-of-band emergency patch on January 26, 2026, for all affected Office versions. Organizations should immediately apply the latest security updates via Microsoft Update or the Office Security Releases page (https://aka.ms/OfficeSecurityReleases). CISA's KEV entry specifies: apply vendor mitigations for Office 2021; apply interim mitigations for Office 2016 and 2019 until final patches are available. For organizations unable to patch immediately, restrict opening of Office documents from untrusted sources, enforce Protected View policies via Group Policy, and consider blocking RTF file execution. 0patch also released micropatches for unsupported Office versions (Microsoft MSRC, CISA KEV, 0patch).
The vulnerability generated significant industry attention due to its emergency out-of-band patch and immediate nation-state exploitation. Dustin Childs (ZDI) and other prominent researchers highlighted the urgency on Bluesky and social media. Security vendors including Sophos, Trellix, Zscaler, Malwarebytes, Cisco Talos, and ESET published detailed analyses. CERT-UA, CERT-EU, NHS Digital, HKCERT, and multiple national CERTs issued advisories. The Register, Ars Technica, BleepingComputer, The Hacker News, and SecurityWeek provided extensive coverage. Community sentiment on Reddit (r/sysadmin, r/blueteamsec) emphasized urgency given active exploitation. Trellix's attribution of APT28's maritime/transport targeting and Zscaler's Operation Neusploit report were widely cited (Sophos, Trellix, CERT-EU).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."