• News/
  • https://www.theregister.com/2026/01/27/office_zeroday_exploited_in_the/

Office zero-day exploited, forces Microsoft OOB patch

The Register
·
Carly Page
·
Published Jan 27, 2026
·
Updated

Updated Microsoft has issued an emergency Office patch after confirming a zero-day flaw is already being used in real world attacks. The flaw, tracked as CVE-2026-21509, and slapped with a CVSS score of 7.8, falls into Microsoft's "security feature bypass" bucket. In practice, this means attackers can dodge protections that are supposed to stop unsafe legacy components from running. Those components include COM and OLE – old Windows plumbing that's been at the heart of document-based attacks for years and clearly hasn't earned its retirement yet. According to Microsoft, exploitation doesn't hinge on the Office preview pane – often a red flag in past campaigns – but still requires little effort once a victim is persuaded to open a booby-trapped file. In its advisory, the company describes the issue as a case of "reliance on untrusted inputs in a security decision," a polite way of saying Office can be talked into doing things it shouldn't. "Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally," Microsoft said. "An attacker must send a user a malicious Office file and convince them to open it." The flaw hits most current Office builds, from Office 2016 and 2019 through to the LTSC releases and Microsoft 365 Apps for Enterprise. Updates are out for newer versions, but anyone still running Office 2016 or 2019 is stuck waiting. Microsoft says fixes for those editions aren't ready yet and will s...

Read full article

Affected Software

3 affected components
Microsoft Office>=2016
Microsoft Microsoft 365 Apps for Enterprise
Microsoft Office LTSC
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in Microsoft Office that has been exploited in real-world attacks.

2

What is the tracked identifier of the vulnerability mentioned?

The vulnerability is tracked as CVE-2026-21509.

3

What security implications does the article highlight?

The article highlights the risk posed by the zero-day flaw due to its exploitation in active attacks, necessitating an emergency patch from Microsoft.

4

What products are affected by the zero-day vulnerability?

The affected software includes Microsoft Office (2016 and later), Microsoft 365 Apps for Enterprise, and Microsoft Office LTSC.

5

What is the severity score of the vulnerability according to CVSS?

The vulnerability has a CVSS score of 7.8, indicating significant security risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203