Vulnerability record · CVE-2026-21514 · published 10 February 2026
CVE-2026-21514: Microsoft Word security feature bypass via untrusted input
Microsoft · 365 Apps
Microsoft Word relies on untrusted inputs when making a security decision, allowing an attacker to bypass a security feature. The flaw affects Microsoft 365 Apps and the Office Long Term Servicing Channel, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt attention despite a modest EPSS score.
Description
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with known exploitation and a CVSS of 7.8, but requires local access and user interaction, limiting mass exploitation.
What it is
Microsoft Word relies on untrusted inputs when making a security decision, allowing an attacker to bypass a security feature. The flaw affects Microsoft 365 Apps and the Office Long Term Servicing Channel, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt attention despite a modest EPSS score.
Impact
An attacker can bypass a Word security feature, and the CVSS vector indicates high confidentiality, integrity and availability impact on the local system. The exact feature bypassed and the resulting capability are not detailed in the record.
Attack surface
The vector is local (AV:L) with no privileges required (PR:N) but user interaction required (UI:R), meaning the attacker must get a user to open or interact with a crafted file on the target machine. No remote or unauthenticated network path is described.
Exploitation
CVE-2026-21514 was added to CISA KEV on 2026-02-10 with a remediation due date of 2026-03-03, indicating known exploitation, though the EPSS 30-day probability is low at roughly 1.5 percent. No ransomware campaign use is documented.
What to do
- Apply the Microsoft update listed in the MSRC advisory for CVE-2026-21514 as the first action.
- Follow CISA BOD 22-01 guidance and the KEV required action, including discontinuing use if no mitigation is available.
- Restrict opening of untrusted or unsolicited Office documents, especially from email and downloads.
- Enable Protected View and block macros and embedded objects from untrusted sources in Word.
- Track the KEV due date of 2026-03-03 to confirm remediation is complete.
Detection
- Monitor for Word processes spawning unexpected child processes or writing to unusual locations after document open.
- Alert on Office documents received from external senders that trigger Protected View bypass or security prompt suppression.
- Review endpoint telemetry for anomalous file or registry activity originating from WINWORD.EXE.
- Check patch and version status of Microsoft 365 Apps and Office LTSC installations against the MSRC advisory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-21514 to the Known Exploited Vulnerabilities catalog on 10 February 2026 as "Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 March 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21514 | US Government Resource |
Track CVE-2026-21514 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-21514), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.