Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks
Microsoft released emergency out-of-band security updates on Mon, Jan 26, 2026, addressing CVE-2026-21509. This zero-day security feature bypass vulnerability in Microsoft Office is currently being exploited by attackers.
Microsoft released emergency out-of-band security updates on Mon, Jan 26, 2026, addressing CVE-2026-21509. This zero-day security feature bypass vulnerability in Microsoft Office is currently being exploited by attackers.
The vulnerability has been rated as "Important" with a CVSS v3.1 base score of 7.8. It exploits untrusted inputs in security decisions to bypass OLE mitigations that protect against vulnerable COM/OLE controls.
CVE-2026-21509 allows local attackers to bypass Office protections by tricking users into opening malicious files through phishing or social engineering . The attack vector is characterized by low complexity, no required privileges, and user interaction, resulting in significant impacts on confidentiality, integrity, and availability.
The Microsoft Threat Intelligence Center (MSTIC) has confirmed exploitation detection, marking it as the second actively exploited zero-day addressed this month following Patch Tuesday updates.
The vulnerability affects both legacy and current Office editions. Patches were deployed on Jan 26, 2026.
Product Architecture KB Article Build
Office 2016 64-bit 5002713 16.0.5539.1001
Microsoft released emergency out-of-band security updates on Mon, Jan 26, 2026, addressing CVE-2026-21509.
Office 2016 32-bit 5002713 16.0.5539.1001
Office LTSC 2024 64/32-bit N/A Latest
Office LTSC 2021 64/32-bit N/A Latest
M365 Apps Enterprise 64/32-bit N/A Latest
Office 2019 64/32-bit N/A 16.0.10417.20095
To verify builds, navigate to File > Account > About.
Office 2021 and newer versions automatically receive service-side protection after a restart. Office 2016 and 2019 require manual updates or registry modifications.
To modify the registry, add the DWORD "Compatibility Flags" with a value of 400 under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}. Adjust paths for architecture or Click-to-Run installations. Back up the registry before making changes and restart applications after modifications.
Organizations are advised to prioritize patching, enable automatic updates, and monitor for phishing indicators of compromise, such as suspicious Office attachments. Threat actors are known to utilize this vector for ransomware and advanced persistent threat (APT) initial access. Deploy endpoint detection and response (EDR) solutions to identify COM/OLE anomalies. While no public proof of concept or actor names have been released yet, monitor the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog for updates.
Based on reporting by Cyber Security News.
