← Vulnerability feed

Vulnerability record · CVE-2026-21514 · published 10 February 2026

CVE-2026-21514: Microsoft Word security feature bypass via untrusted input

Microsoft · 365 Apps

Microsoft Word relies on untrusted inputs when making a security decision, allowing an attacker to bypass a security feature. The flaw affects Microsoft 365 Apps and the Office Long Term Servicing Channel, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt attention despite a modest EPSS score.

7.8 CVSS 3.1 High CISA KEV since 10 Feb 2026 EPSS 1.5% · top 26.1% CWE-807 · CWE-807
7.8CVSS 3.1 base score
1.5%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is in CISA KEV with known exploitation and a CVSS of 7.8, but requires local access and user interaction, limiting mass exploitation.

What it is

Microsoft Word relies on untrusted inputs when making a security decision, allowing an attacker to bypass a security feature. The flaw affects Microsoft 365 Apps and the Office Long Term Servicing Channel, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so it warrants prompt attention despite a modest EPSS score.

Impact

An attacker can bypass a Word security feature, and the CVSS vector indicates high confidentiality, integrity and availability impact on the local system. The exact feature bypassed and the resulting capability are not detailed in the record.

Attack surface

The vector is local (AV:L) with no privileges required (PR:N) but user interaction required (UI:R), meaning the attacker must get a user to open or interact with a crafted file on the target machine. No remote or unauthenticated network path is described.

Exploitation

CVE-2026-21514 was added to CISA KEV on 2026-02-10 with a remediation due date of 2026-03-03, indicating known exploitation, though the EPSS 30-day probability is low at roughly 1.5 percent. No ransomware campaign use is documented.

What to do

  • Apply the Microsoft update listed in the MSRC advisory for CVE-2026-21514 as the first action.
  • Follow CISA BOD 22-01 guidance and the KEV required action, including discontinuing use if no mitigation is available.
  • Restrict opening of untrusted or unsolicited Office documents, especially from email and downloads.
  • Enable Protected View and block macros and embedded objects from untrusted sources in Word.
  • Track the KEV due date of 2026-03-03 to confirm remediation is complete.

Detection

  • Monitor for Word processes spawning unexpected child processes or writing to unusual locations after document open.
  • Alert on Office documents received from external senders that trigger Protected View bypass or security prompt suppression.
  • Review endpoint telemetry for anomalous file or registry activity originating from WINWORD.EXE.
  • Check patch and version status of Microsoft 365 Apps and Office LTSC installations against the MSRC advisory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-21514 to the Known Exploited Vulnerabilities catalog on 10 February 2026 as "Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 March 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21514 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21413Microsoft Outlook improper input validation remote code executionCVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink…KEVEPSS 95%analysed9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2024-38189Microsoft Project Remote Code Execution via Improper Input ValidationMicrosoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code …KEVEPSS 8.2%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed7.8CVE-2026-21509Microsoft Office untrusted input security feature bypassMicrosoft Office relies on untrusted inputs when making a security decision, letting an unauthorized attacker bypass a security feature locally. The …KEVEPSS 73%analysed7.8CVE-2021-42292Microsoft Excel security feature bypass via crafted fileCVE-2021-42292 is a security feature bypass in Microsoft Excel and related Office products. The record gives only a one-line description, so the exac…KEVEPSS 43%analysed7.8CVE-2021-38646Microsoft Office Access Connectivity Engine remote code executionThe Microsoft Office Access Connectivity Engine contains a remote code execution flaw. The record gives no root-cause detail beyond the CWE being mar…KEVEPSS 8.0%analysed7.3CVE-2024-38226Microsoft Publisher security feature bypass via local attackerCVE-2024-38226 is a security feature bypass in Microsoft Publisher, affecting Office 2019, Office Long Term Servicing Channel, and Publisher. The fla…KEVEPSS 2.7%analysed

Source: NIST National Vulnerability Database (record CVE-2026-21514), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.