• News/
  • https://www.zdnet.com/article/microsoft-office-emergency-patch-fixes-zero-day-flaw/

Microsoft's latest zero-day patch blocks a viral Office document hack - how to protect your PC ASAP

ZDNet
·
Lance Whitney
·
Published Jan 30, 2026
·
Updated

Follow ZDNET: Add us as a preferred source on Google. Microsoft has issued an emergency patch designed to resolve a zero-day security vulnerability affecting several versions of Microsoft Office. Already exploited in the wild, the flaw could allow an attacker to skirt past Office's built-in security measures and send victims a malicious document. In a note published earlier this week, Microsoft revealed details behind the flaw, known as a Microsoft Office Security Feature Bypass Vulnerability. Also: Why you need Microsoft's new emergency Windows patch - and the black-screen bug to watch for Tagged as CVE-2026-21509, this vulnerability bypasses the OLE mitigations in Microsoft 365 and Microsoft Office. OLE (Object Linking and Embedding) lets Office link to or embed files, text, images, and other content from external applications. The OLE mitigations are supposed to prevent hackers from exploiting these controls to send malicious files and documents. Attackers take advantage of such vulnerabilities to launch phishing campaigns in which you're prompted to open a malicious file attachment. With the built-in security not working properly, the malicious code in the file can then easily infect your system. Various versions of Microsoft 365 and Office are affected, including Microsoft Office 2016 (32-bit), Microsoft Office 2019 (32-bit and 64-bit), Microsoft 365 Apps for Enterprise (32-bit and 64-bit), Microsoft Office LTSC 2021 (32-bit and 64-bit), and Microsoft Office LTSC 2024 (3...

Read full article

Affected Software

1 affected component
Microsoft Office=2016 (32-bit), =2019 (32-bit), =2019 (64-bit), =LTSC 2021 (32-bit), =LTSC 2021 (64-bit), =LTSC 2024 (32-bit), =LTSC 2024 (64-bit), =365 Apps for Enterprise (32-bit), =365 Apps for Enterprise (64-bit)
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses an emergency patch released by Microsoft to address a zero-day vulnerability in Microsoft Office.

2

What security implications are discussed?

The article highlights the risk of a viral Office document hack that could lead to potential exploitation if the patch is not applied.

3

What versions of Microsoft Office are affected by the zero-day flaw?

The affected versions include Microsoft Office 2016, 2019, LTSC 2021, LTSC 2024, and Office 365 Apps for Enterprise.

4

How can users protect their systems against this vulnerability?

Users are advised to install the emergency patch provided by Microsoft as soon as possible.

5

What type of vulnerability is addressed by the emergency patch?

The emergency patch addresses a zero-day vulnerability, which is an actively exploited security flaw.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203