CVE-2026-21509: Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Other sources
Microsoft Office Security Feature Bypass Vulnerability
— Microsoft
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5539.1001Patch KB5002713 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20095
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21509?
CVE-2026-21509 is classified as a security feature bypass vulnerability in Microsoft Office.
What versions of Microsoft Office are affected by CVE-2026-21509?
CVE-2026-21509 affects Microsoft Office 2016, 2019, LTSC 2021, and Microsoft 365 Apps for Enterprise across both 32-bit and 64-bit editions.
How do I fix CVE-2026-21509?
To fix CVE-2026-21509, download and install the security update provided by Microsoft for the affected version of Office.
What are the potential risks of CVE-2026-21509?
Exploitation of CVE-2026-21509 could allow unauthorized attackers to bypass security features in Microsoft Office.
Is CVE-2026-21509 actively being exploited in the wild?
CVE-2026-21509 has been identified in the context of known exploits as reported by security advisories.