
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21514 is a security feature bypass vulnerability in Microsoft Office Word classified under CWE-807 (Reliance on Untrusted Inputs in a Security Decision). It allows an unauthorized attacker to bypass OLE (Object Linking and Embedding) security mitigations locally by convincing a user to open a malicious Word document, enabling arbitrary code execution without elevated privileges. Affected products include Microsoft 365 Apps for Enterprise (x86/x64), Office 2021 (Windows and macOS), Office 2024 (Windows and macOS), and Office Long Term Servicing Channel (2021 and 2024 on both platforms). The vulnerability was publicly disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, CISA KEV).
The root cause is CWE-807: Reliance on Untrusted Inputs in a Security Decision — specifically, Microsoft Office Word improperly trusts attacker-controlled input when making OLE security decisions, allowing the bypass of protections designed to prevent execution of embedded or linked objects from untrusted sources. The attack vector is local with low attack complexity, requiring no privileges but necessitating user interaction (opening a crafted Word document). Exploitation mechanics involve delivering a specially crafted .docx or similar Office file that, when opened, causes Word to evaluate untrusted OLE-related inputs and bypass security controls, ultimately enabling arbitrary code execution in the context of the logged-in user. A GitHub repository (ChaitanyaHaritash/CVE-2026-21514_CVE-2026-21510) referencing combined PoC material for this and a related vulnerability appeared in late May 2026, and a detailed FAQ/technical write-up was published on Security Boulevard in March 2026 (Microsoft MSRC, Security Boulevard FAQ).
Successful exploitation results in high impact to confidentiality, integrity, and availability — an attacker can achieve arbitrary code execution on the victim's system with the privileges of the current user, potentially enabling full system compromise. Because no elevated privileges are required, any standard user who opens a malicious document is at risk, making this particularly dangerous in enterprise environments where Office documents are routinely shared. The vulnerability could facilitate data exfiltration, installation of malware or ransomware (CISA notes unknown ransomware campaign association), and lateral movement within a network if the compromised account has access to shared resources (CISA KEV, Feedly/Microsoft).
.docx or similar) that embeds or references an OLE object with attacker-controlled inputs designed to bypass Word's OLE security decision logic.%TEMP%, %APPDATA%, or Office cache directories following document opening; new executables or scripts created by WINWORD.EXE child processes; presence of crafted .docx files with embedded OLE objects from untrusted sources.WINWORD.EXE (e.g., cmd.exe, powershell.exe, mshta.exe, wscript.exe, curl.exe); Office processes making network connections not typical for document rendering.Microsoft released patches for all affected products on February 10, 2026, as part of the February 2026 Patch Tuesday security update. Organizations should immediately apply the security update to all systems running Microsoft 365 Apps for Enterprise, Office 2021, Office 2024, and Office Long Term Servicing Channel (2021 and 2024) on both Windows and macOS. CISA set a remediation due date of March 3, 2026, for federal agencies under BOD 22-01. As interim mitigations, organizations should implement application whitelisting, restrict opening of Office documents from untrusted sources, educate users about phishing risks, and monitor for suspicious Office process behavior. No Microsoft-provided configuration-only workaround has been publicly documented; patching is the primary remediation (Microsoft MSRC, CISA KEV).
The February 2026 Patch Tuesday release, which included CVE-2026-21514 among six actively exploited zero-days, drew significant attention from the security community. Researchers at Tenable, Qualys, Rapid7, CrowdStrike, and Sophos all highlighted the vulnerability in their Patch Tuesday analyses, with Tenable's Satnam Narang providing commentary on the unusually high number of zero-days (Tenable Blog, Qualys Blog). CRN reported that a researcher described the number of zero-days as 'extraordinarily high.' Dark Reading, BleepingComputer, The Hacker News, and Forbes all covered the patch release prominently, emphasizing the active exploitation status. Social media discussion on Mastodon and Bluesky noted the CISA KEV addition in real time. A dedicated Security Boulevard FAQ post in March 2026 provided deeper technical context on the OLE bypass mechanism (Security Boulevard FAQ, Dark Reading).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."