Vulnerability record · CVE-2026-21509 · published 26 January 2026
CVE-2026-21509: Microsoft Office untrusted input security feature bypass
Microsoft · 365 Apps
Microsoft Office relies on untrusted inputs when making a security decision, letting an unauthorized attacker bypass a security feature locally. The flaw is tracked in CISA's KEV catalog with a 2026-02-16 remediation due date, so it is being exploited in the wild. It matters because a bypass of Office protections can defeat the controls defenders rely on to block malicious documents.
Description
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with confirmed exploitation, a near-top EPSS score and a short remediation deadline, despite the local vector requiring user interaction.
What it is
Microsoft Office relies on untrusted inputs when making a security decision, letting an unauthorized attacker bypass a security feature locally. The flaw is tracked in CISA's KEV catalog with a 2026-02-16 remediation due date, so it is being exploited in the wild. It matters because a bypass of Office protections can defeat the controls defenders rely on to block malicious documents.
Impact
An attacker gains the ability to evade an Office security feature, which can enable follow-on code execution or malicious content handling with high confidentiality, integrity and availability impact per the CVSS vector. The bypass itself is a control defeat rather than a direct privilege escalation.
Attack surface
The vector is local (AV:L) with no privileges required (PR:N) but user interaction required (UI:R), meaning the victim must open or interact with a crafted file or content. No remote network path or authentication is needed beyond that interaction.
Exploitation
CISA added this to KEV on 2026-01-26 with a 2026-02-16 due date, confirming known exploitation; EPSS is 0.72554 (99.4th percentile), indicating high predicted exploitation activity. No ransomware campaign use is documented.
What to do
- Apply the Microsoft MSRC update for CVE-2026-21509 immediately across Office, Microsoft 365 Apps and Office LTSC installations.
- Follow CISA BOD 22-01 guidance and the vendor's required actions; discontinue use of the product if no mitigation is available.
- Block or restrict untrusted document types and macros at email and web gateways to reduce the interaction vector.
- Use the published third-party mitigation script where patching cannot be completed immediately.
- Track KEV due date 2026-02-16 and verify remediation completion before it.
Detection
- Monitor for Office processes spawning child processes or loading unusual modules after document open.
- Alert on Office files opened from email attachments, downloads or temp directories that trigger security-prompt bypass behavior.
- Use the published Vicarius detection script to hunt for indicators of the bypass.
- Review endpoint telemetry for Office security feature prompts being suppressed or skipped unexpectedly.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-21509 to the Known Exploited Vulnerabilities catalog on 26 January 2026 as "Microsoft Office Security Feature Bypass Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 February 2026.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 | Vendor Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerab | Third Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnera | MitigationThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509 | US Government Resource |
Track CVE-2026-21509 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-21509), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.