Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks

Microsoft released emergency out-of-band security updates on Mon, Jan 26, 2026, addressing CVE-2026-21509. This zero-day security feature bypass vulnerability in Microsoft Office is currently being exploited by attackers.

Microsoft released emergency out-of-band security updates on Mon, Jan 26, 2026, addressing CVE-2026-21509. This zero-day security feature bypass vulnerability in Microsoft Office is currently being exploited by attackers.

The vulnerability has been rated as "Important" with a CVSS v3.1 base score of 7.8. It exploits untrusted inputs in security decisions to bypass OLE mitigations that protect against vulnerable COM/OLE controls.

CVE-2026-21509 allows local attackers to bypass Office protections by tricking users into opening malicious files through phishing or social engineering . The attack vector is characterized by low complexity, no required privileges, and user interaction, resulting in significant impacts on confidentiality, integrity, and availability.

The Microsoft Threat Intelligence Center (MSTIC) has confirmed exploitation detection, marking it as the second actively exploited zero-day addressed this month following Patch Tuesday updates.

The vulnerability affects both legacy and current Office editions. Patches were deployed on Jan 26, 2026.

Product Architecture KB Article Build

Office 2016 64-bit 5002713 16.0.5539.1001

Microsoft released emergency out-of-band security updates on Mon, Jan 26, 2026, addressing CVE-2026-21509.
Mark Jensen · Thehackingpost

Office 2016 32-bit 5002713 16.0.5539.1001

Office LTSC 2024 64/32-bit N/A Latest

Office LTSC 2021 64/32-bit N/A Latest

M365 Apps Enterprise 64/32-bit N/A Latest

Office 2019 64/32-bit N/A 16.0.10417.20095

Advertisement

To verify builds, navigate to File > Account > About.

Office 2021 and newer versions automatically receive service-side protection after a restart. Office 2016 and 2019 require manual updates or registry modifications.

To modify the registry, add the DWORD "Compatibility Flags" with a value of 400 under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}. Adjust paths for architecture or Click-to-Run installations. Back up the registry before making changes and restart applications after modifications.

Organizations are advised to prioritize patching, enable automatic updates, and monitor for phishing indicators of compromise, such as suspicious Office attachments. Threat actors are known to utilize this vector for ransomware and advanced persistent threat (APT) initial access. Deploy endpoint detection and response (EDR) solutions to identify COM/OLE anomalies. While no public proof of concept or actor names have been released yet, monitor the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog for updates.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories