CVE-2026-21509 KEV
7.8
HIGH · CVSS 3.1 · EPSS 72.9% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2026-02-16.
Description
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 72.87% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-807 |
| On CISA KEV | yes — remediate by 2026-02-16 |
| Public exploit | none known |
| Published | 2026-01-26 |
| Last modified | 2026-06-25 |
CISA KEV
| Name | Microsoft Office Security Feature Bypass Vulnerability |
|---|---|
| Added | 2026-01-26 |
| Due | 2026-02-16 |
| Vendor / product | Microsoft / Office |
| Ransomware use | none reported |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | 365 apps |
| microsoft | office |
| microsoft | office long term servicing channel |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
- https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability
- https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509
→ the Explorer · watch your stack · NVD