← Vulnerability feed

Vulnerability record · CVE-2026-21509 · published 26 January 2026

CVE-2026-21509: Microsoft Office untrusted input security feature bypass

Microsoft · 365 Apps

Microsoft Office relies on untrusted inputs when making a security decision, letting an unauthorized attacker bypass a security feature locally. The flaw is tracked in CISA's KEV catalog with a 2026-02-16 remediation due date, so it is being exploited in the wild. It matters because a bypass of Office protections can defeat the controls defenders rely on to block malicious documents.

7.8 CVSS 3.1 High CISA KEV since 26 Jan 2026 EPSS 73% · top 0.6% CWE-807 · CWE-807
7.8CVSS 3.1 base score
73%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
4References
25 Jun 2026Last modified by NVD

Description

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with confirmed exploitation, a near-top EPSS score and a short remediation deadline, despite the local vector requiring user interaction.

What it is

Microsoft Office relies on untrusted inputs when making a security decision, letting an unauthorized attacker bypass a security feature locally. The flaw is tracked in CISA's KEV catalog with a 2026-02-16 remediation due date, so it is being exploited in the wild. It matters because a bypass of Office protections can defeat the controls defenders rely on to block malicious documents.

Impact

An attacker gains the ability to evade an Office security feature, which can enable follow-on code execution or malicious content handling with high confidentiality, integrity and availability impact per the CVSS vector. The bypass itself is a control defeat rather than a direct privilege escalation.

Attack surface

The vector is local (AV:L) with no privileges required (PR:N) but user interaction required (UI:R), meaning the victim must open or interact with a crafted file or content. No remote network path or authentication is needed beyond that interaction.

Exploitation

CISA added this to KEV on 2026-01-26 with a 2026-02-16 due date, confirming known exploitation; EPSS is 0.72554 (99.4th percentile), indicating high predicted exploitation activity. No ransomware campaign use is documented.

What to do

  • Apply the Microsoft MSRC update for CVE-2026-21509 immediately across Office, Microsoft 365 Apps and Office LTSC installations.
  • Follow CISA BOD 22-01 guidance and the vendor's required actions; discontinue use of the product if no mitigation is available.
  • Block or restrict untrusted document types and macros at email and web gateways to reduce the interaction vector.
  • Use the published third-party mitigation script where patching cannot be completed immediately.
  • Track KEV due date 2026-02-16 and verify remediation completion before it.

Detection

  • Monitor for Office processes spawning child processes or loading unusual modules after document open.
  • Alert on Office files opened from email attachments, downloads or temp directories that trigger security-prompt bypass behavior.
  • Use the published Vicarius detection script to hunt for indicators of the bypass.
  • Review endpoint telemetry for Office security feature prompts being suppressed or skipped unexpectedly.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-21509 to the Known Exploited Vulnerabilities catalog on 26 January 2026 as "Microsoft Office Security Feature Bypass Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 February 2026.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21509 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21413Microsoft Outlook improper input validation remote code executionCVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink…KEVEPSS 95%analysed9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2024-38189Microsoft Project Remote Code Execution via Improper Input ValidationMicrosoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code …KEVEPSS 8.2%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed

Source: NIST National Vulnerability Database (record CVE-2026-21509), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.