CVE-2026-21514
📛 CVE Title
Microsoft Word Security Feature Bypass Vulnerability
Description
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 7.8 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C- Effective score
- 7.8 / 10 HIGH source: CNA overview
- MSRC score
- 7.8 / 10 HIGH MS rating: Important · Security Feature Bypass
- CWE(s)
-
CWE-807 - Reserved
- 2025-12-30
- Published
- 2026-02-10 08:00 UTC
- Last updated
- 2026-02-10 08:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/21xxx/CVE-2026-21514.json
- Linked Threat
- CVE-2026-21514 — Microsoft Office: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
CISA Known Exploited Vulnerabilities CISA KEV
CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.
- Vulnerability name
- Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
- Vendor / project
- Microsoft
- Product
- Office
- Date added to KEV
- 2026-02-10
- Remediation due
- 2026-03-03
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware campaign use
- Unknown
- CISA notes
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21514
- CISA listing
- www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-02-10 18:16:33 UTC
- NVD last modified
- 2026-02-11 15:47:04 UTC
- NVD CVSS v3.1
- 7.8 / 10 HIGH source: secure@microsoft.com
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0496 (probability of exploitation in next 30 days)
- EPSS percentile
- 89.77% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD / KEV / EPSS data refreshed 2026-05-25 04:03 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-7334 - Assigner
- microsoft
- Published
- Feb 10, 2026, 5:51:34 PM
- Updated
- May 11, 2026, 9:25:35 PM
- EUVD base score (CVSS 3.1)
-
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C - EUVD-reported EPSS
- 4.9600
- Vendors
- Microsoft
- Products
-
Microsoft Office LTSC 2021 (16.0.1 <https://aka.ms/OfficeSecurityReleases)Microsoft Office LTSC 2024 (16.0.0 <https://aka.ms/OfficeSecurityReleases)Microsoft Office LTSC for Mac 2024 (16.0.0 <16.106.26020821)Microsoft 365 Apps for Enterprise (16.0.1 <https://aka.ms/OfficeSecurityReleases)Microsoft Office LTSC 2021 (16.0.1 <https://aka.ms/OfficeSecurityReleases)Microsoft Office LTSC 2024 (16.0.0 <https://aka.ms/OfficeSecurityReleases)Microsoft 365 Apps for Enterprise (16.0.1 <https://aka.ms/OfficeSecurityReleases)Microsoft Office LTSC for Mac 2021 (16.0.1 <16.106.26020821)Microsoft Office LTSC for Mac 2021 (16.0.1 <16.106.26020821)Microsoft Office LTSC for Mac 2024 (16.0.0 <16.106.26020821)
- Aliases
-
GHSA-cjj3-m869-748g
ENISA description: Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-15 03:05 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Security Feature Bypass
- MS CVSS base score
- 7.8 / 10 (temporal 7.2)
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected
- Release
- 2026-Feb
Microsoft remediations / KB articles (3)
- Click to Run — Vendor Fix / Security Update (fixed build https://aka.ms/OfficeSecurityReleases)
- https://docs.microsoft.com/en-us/officeupdates/office365-proplus-security-updates — None Available / Click to Run
- Release Notes — Vendor Fix / Security Update (fixed build 16.106.26020821)
Microsoft FAQ (3)
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office which protect users from vulnerable COM/OLE controls.
Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Affected products (5)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise |
16.0.1 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office LTSC 2021 |
16.0.1 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office LTSC 2024 |
16.0.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office LTSC for Mac 2021 |
16.0.1 (affected)
|
— |
| Microsoft | Microsoft Office LTSC for Mac 2024 |
16.0.0 (affected)
|
— |
Affected products — CPE 2.3 (8) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Microsoft Word Security Feature Bypass Vulnerability vendor-advisorypatch
Web references (6)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- None Available msrc
- Release Notes msrc
- MSRC update guide: CVE-2026-21514 msrc
- http://cwe.mitre.org/data/definitions/807.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2026-21514 rapid7:attackerkb.com
- https://www.cve.org/CVERecord?id=CVE-2026-21514 rapid7:www.cve.org
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 secure@microsoft.com Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21514 134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government Resource
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| cve |
CVE-2026-21514
|
no local data | 2026-05-14 02:58 UTC |
| cwe |
CWE-807
|
no local data | 2026-05-14 02:58 UTC |
Remediations (9)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.upguard.com
CVE-2026-21514 is a high-severity security bypass in Microsoft Office Word (CVSS 7.8) that is actively exploited in the wild.
2026-05-14 17:20 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-05-14 17:20 UTC -
web:nvd.nist.gov
An official website of the United States government NVD MENU
2026-05-14 17:20 UTC -
web:securityboulevard.com
An N-day vulnerability in Microsoft Word exposes nearly 14 million assets. Attackers can exploit this flaw to bypass security prompts, enabling deployment of malware and establishing persistent access without triggering user warnings.Key takeaways:CVE- 2026 - 21514 is a Microsoft Word n-day that bypasses OLE and Mark-of-the-Web protections, executing payloads silently without triggering user ...
2026-05-14 17:20 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.
2026-05-14 17:20 UTC -
web:cyberpress.org
Microsoft's February 2026 Patch Tuesday dropped with major urgency, fixing 54 security flaws across Windows, Office, Exchange, Azure, and more. The standout issue? Six zero-day vulnerabilities are already under active attack in the wild. These are bugs hackers exploited before Microsoft could patch them. IT teams must apply these updates now to avoid breaches. Zero-days let attackers slip ...
2026-05-14 17:20 UTC -
web:www.malwarebytes.com
May's Patch Tuesday may not be the giant release many expected, but there are still plenty of important fixes that shouldn't be ignored.
2026-05-14 17:20 UTC -
web:www.sentinelone.com
CVE-2026-21514 is an authentication bypass vulnerability in Microsoft 365 Apps. Learn about its impact, affected versions, and mitigation methods.
2026-05-14 17:20 UTC -
CISA KEV
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-03-03 Known ransomware campaign use: Unknown
2026-05-14 01:13 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-21514.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-21514",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-02-11T04:56:01.104546Z",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2026-02-10",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21514"
},
"type": "kev"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-02-26T14:44:45.208Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21514"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-02-10T00:00:00.000Z",
"value": "CVE-2026-21514 added to CISA KEV"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft 365 Apps for Enterprise",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "16.0.1",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Office LTSC 2021",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "16.0.1",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Office LTSC 2024",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
},
{
"product": "Microsoft Office LTSC for Mac 2021",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.106.26020821",
"status": "affected",
"version": "16.0.1",
"versionType": "custom"
}
]
},
{
"product": "Microsoft Office LTSC for Mac 2024",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.106.26020821",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "16.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*",
"versionEndExcluding": "16.106.26020821",
"versionStartIncluding": "16.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "16.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "16.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*",
"versionEndExcluding": "16.106.26020821",
"versionStartIncluding": "16.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-02-10T16:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-807",
"description": "CWE-807: Reliance on Untrusted Inputs in a Security Decision",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-05-11T21:25:35.049Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Microsoft Word Security Feature Bypass Vulnerability",
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514"
}
],
"title": "Microsoft Word Security Feature Bypass Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2026-21514",
"datePublished": "2026-02-10T17:51:34.153Z",
"dateReserved": "2025-12-30T18:10:54.845Z",
"dateUpdated": "2026-05-11T21:25:35.049Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}