CVE-2026-21509
📛 CVE Title
Microsoft Office Security Feature Bypass Vulnerability
Description
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 7.8 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C- Effective score
- 7.8 / 10 HIGH source: CNA overview
- MSRC score
- 7.8 / 10 HIGH MS rating: Important · Security Feature Bypass
- CWE(s)
-
CWE-807 - Reserved
- 2025-12-30
- Published
- 2026-01-26 08:00 UTC
- Last updated
- 2026-01-29 08:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/21xxx/CVE-2026-21509.json
- Linked Threat
- CVE-2026-21509 — Microsoft Office: Microsoft Office Security Feature Bypass Vulnerability
CISA Known Exploited Vulnerabilities CISA KEV
CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.
- Vulnerability name
- Microsoft Office Security Feature Bypass Vulnerability
- Vendor / project
- Microsoft
- Product
- Office
- Date added to KEV
- 2026-01-26
- Remediation due
- 2026-02-16
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware campaign use
- Unknown
- CISA notes
- Please adhere to Microsoft’s recommended guidelines to address this vulnerability. Implement all final mitigations provided by the vendor for Office 2021, and apply the interim corresponding mitigations for Office 2016 and Office 2019 until the final patch becomes available. For more information please see: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21509
- CISA listing
- www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-01-26 18:16:38 UTC
- NVD last modified
- 2026-02-11 15:40:33 UTC
- NVD CVSS v3.1
- 7.8 / 10 HIGH source: secure@microsoft.com
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.1144 (probability of exploitation in next 30 days)
- EPSS percentile
- 93.69% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD / KEV / EPSS data refreshed 2026-05-25 03:56 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-4666 - Assigner
- microsoft
- Published
- Jan 26, 2026, 5:06:35 PM
- Updated
- Apr 1, 2026, 1:49:28 PM
- EUVD base score (CVSS 3.1)
-
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C - EUVD-reported EPSS
- 15.2900
- Vendors
- Microsoft
- Products
-
Microsoft Office 2019 (19.0.0 <16.0.10417.20095)Microsoft Office LTSC 2021 (16.0.1 <https://aka.ms/OfficeSecurityReleases)Microsoft Office 2016 (-)Microsoft Office LTSC 2024 (16.0.0 <https://aka.ms/OfficeSecurityReleases)Microsoft 365 Apps for Enterprise (16.0.1 <https://aka.ms/OfficeSecurityReleases)Microsoft Office 2016 (16.0.0 <16.0.5539.1001)Microsoft Office 2019 (-)
- Aliases
-
GHSA-ch84-h92g-mw93
ENISA description: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-31 03:00 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Security Feature Bypass
- MS CVSS base score
- 7.8 / 10 (temporal 7.2)
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected
- Release
- 2026-Jan
Microsoft remediations / KB articles (7)
- Click to Run — Vendor Fix / Security Update (fixed build 16.0.10417.20095)
- https://learn.microsoft.com/en-us/officeupdates/update-history-office-2019 — None Available / Click to Run
- https://docs.microsoft.com/en-us/officeupdates/office365-proplus-security-updates — None Available / Click to Run
- 5002713 — Vendor Fix / Security Update (fixed build 16.0.5539.1001)
- https://support.microsoft.com/help/5002713 — None Available / 5002713
- <p><a href="https://www.microsoft.com/en-us/msrc/glossary#Mitigation">Mitigation</a> refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of exploitation of a vulnerability.</p> <p><strong>The following mitigating factors might be helpful in your situation:</strong></p> <p>Customers running Microsoft 365 Apps, Office 2021 and later will be <strong>automatically protected</strong> via a service-side change, but will be required to <strong>restart</strong> their Office applications for this to take effect.</p> <p>Customers running Office 2016 and 2019 are not protected until they install the security update. Customers on these versions can apply the <strong>registry keys</strong> described as follows to be immediately protected.</p> <p>Microsoft Office:</p> <ol> <li>To start <strong>blocking</strong> please add the following registry keys:</li> </ol> <p>Caution: Follow these steps carefully. Serious problems may occur if you modify the registry incorrectly. Before you start we recommend that you have a known good backup of your registry. See this article for more information: <a href="https://support.microsoft.com/en-us/help/322756/how-to-back-up-and-restore-the-registry-in-windows">https://support.microsoft.com/en-us/help/322756/how-to-back-up-and-restore-the-registry-in-windows</a></p> <p>Exit all Microsoft Office applications. Start the Registry Editor by tapping Start (or pressing the Windows key on your keyboard) then typing regedit and pressing enter.</p> <ol start="2"> <li>Locate the <strong>proper registry subkey</strong>. It will be one of the following:</li> </ol> <p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\ (for 64-bit MSI Office, or 32-bit MSI Office on 32-bit Windows)</p> <p>or</p> <p>HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Office\16.0\Common\COM Compatibility\ (for 32-bit MSI Office on 64-bit Windows)</p> <p>or</p> <p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Office\16.0\Common\COM Compatibility\ (for 64-bit Click2Run Office, or 32-bit Click2Run Office on 32-bit Windows)</p> <p>or</p> <p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\WOW6432Node\Microsoft\Office\16.0\Common\COM Compatibility\ (for 32-bit Click2Run Office on 64-bit Windows)</p> <p>Note: The COM Compatibility node may not be present by default. If you don't see it, add it by right-clicking the Common node and choosing Add Key.</p> <ol start="3"> <li>Add a new subkey named {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} by right-clicking the COM Compatibility node and choosing Add Key.</li> </ol> <p>Within that new subkey we're going to add one new value by right-clicking the new subkey and choosing New > DWORD (32-bit) Value.</p> <p>A REG_DWORD hexadecimal value called Compatibility Flags with a value of 400.</p> <p>Exit Registry Editor and start your Office application.</p> <p><strong>Example</strong></p> <p>For example, in Office 2016, 64-bit, on Windows you would locate this registry key:</p> <p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\</p> <p>Note: Remember, if the COM Compatibility node doesn't exist yet you'll need to create it.</p> <p>Then add a subkey with the name {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}.</p> <p>In this case, the resulting path is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}.</p> <p>To that subkey you'll add a REG_DWORD value called Compatibility Flags with a value of 400.</p> — Mitigation
- <p><a href="https://www.microsoft.com/en-us/msrc/glossary#Mitigation">Mitigation</a> refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of exploitation of a vulnerability.</p> <p><strong>The following mitigating factors might be helpful in your situation:</strong></p> <p>Customers on Office 2021 and later are automatically protected without registry change. Registry keys do not apply to Office 2016 or Office 2019. Customers using Office 2016 or Office 2019 will not be protected until they install the upcoming security update.</p> — Mitigation
Microsoft FAQ (5)
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
Are the updates for Microsoft Office 2016 and 2019 currently available?
Yes. As of January 26, 2026, the security update for Microsoft Office 2016 and 2019 is available. Customers running Microsoft Office 2016 and 2019 should ensure the update is installed to be protected from this vulnerability.
How do I know what version of Office 2016 and 2019 I am running?
On January 26 2026, Microsoft released build numbers for Office 2016 16.0.5539.1001 and Office 2019 16.0.10417.20095 to address this vulnerability.
To see what version you have installed:
- In a document click the File tab.
- Click Account in the left hand pane.
- Click About . The top line of the About dialog box will display the Build number.
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office which protect users from vulnerable COM/OLE controls.
Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Affected products (5)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise |
16.0.1 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office 2016 |
16.0.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office 2019 |
19.0.0 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office LTSC 2021 |
16.0.1 (affected)
|
32-bit Systems, x64-based Systems |
| Microsoft | Microsoft Office LTSC 2024 |
16.0.0 (affected)
|
32-bit Systems, x64-based Systems |
Affected products — CPE 2.3 (10) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x64:*cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:*cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x64:*cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x86:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Microsoft Office Security Feature Bypass Vulnerability vendor-advisorypatch
Web references (8)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- 5002713 msrc
- None Available msrc
- None Available msrc
- MSRC update guide: CVE-2026-21509 msrc
- http://cwe.mitre.org/data/definitions/807.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2026-21509 rapid7:attackerkb.com
- https://support.microsoft.com/help/5002713 rapid7:support.microsoft.com
- https://www.cve.org/CVERecord?id=CVE-2026-21509 rapid7:www.cve.org
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 secure@microsoft.com Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509 134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government Resource
- https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability af854a3a-2127-422b-91ae-364da2661108 MitigationThird Party Advisory
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| cwe |
CWE-807
|
no local data | 2026-05-14 02:58 UTC |
| cve |
CVE-2026-21509
|
no local data | 2026-05-14 02:58 UTC |
Remediations (9)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-05-14 18:20 UTC -
web:hivepro.com
CVE-2026-21509 : Discover expert analysis of this Microsoft Office OLE zero-day, including exploit details, mitigation steps, and actionable security recommendations.
2026-05-14 18:20 UTC -
web:orca.security
Microsoft patches CVE-2026-21509 , a high-severity Office zero-day actively exploited in the wild. Learn about the OLE bypass, affected versions, and remediation .
2026-05-14 18:20 UTC -
web:support.microsoft.com
Summary This security update resolves a Microsoft Word security feature bypass vulnerability. To learn more about the vulnerability, see Microsoft Common Vulnerabilities and Exposures CVE-2026-21509 . Note: To apply this security update, you must have the release version of Microsoft Office 2016 installed on the computer.
2026-05-14 18:20 UTC -
web:www.sentinelone.com
CVE-2026-21509 is an authentication bypass vulnerability in Microsoft 365 Apps. Learn about its impact, affected versions, and mitigation methods.
2026-05-14 18:20 UTC -
web:www.isec.news
Microsoft issued out-of-band patches for Office zero-day CVE-2026-21509 , rated 7.8. Service-side protection covers newer builds and a registry workaround is provided for older Office versions. Federal agencies must remediate by February 16, 2026 .
2026-05-14 18:20 UTC -
web:www.notebookcheck.net
Microsoft has released an out-of-band security update to fix an actively exploited Microsoft Office vulnerability tracked as CVE-2026-21509 . The flaw allows attackers to bypass Office security ...
2026-05-14 18:20 UTC -
web:www.penligent.ai
A deep technical analysis of CVE-2026-21509 : Microsoft Office Security Feature Bypass. Includes mitigation scripts, OLE exploit mechanics, and validation strategies using AI automated penetration testing.
2026-05-14 18:20 UTC -
CISA KEV
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-02-16 Known ransomware campaign use: Unknown
2026-05-14 01:13 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-21509.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-21509",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-01-27T13:34:19.867845Z",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2026-01-26",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509"
},
"type": "kev"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-01-27T13:34:26.498Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509"
}
],
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2026-02-10T14:57:48.648Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability"
},
{
"url": "https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability"
}
],
"title": "CVE Program Container",
"x_generator": {
"engine": "ADPogram 0.0.1"
}
}
],
"cna": {
"affected": [
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft 365 Apps for Enterprise",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "16.0.1",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Office 2016",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.5539.1001",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Office 2019",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.10417.20095",
"status": "affected",
"version": "19.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Office LTSC 2021",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "16.0.1",
"versionType": "custom"
}
]
},
{
"platforms": [
"32-bit Systems",
"x64-based Systems"
],
"product": "Microsoft Office LTSC 2024",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "https://aka.ms/OfficeSecurityReleases",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.0.10417.20095",
"versionStartIncluding": "19.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "16.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "16.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*",
"versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
"versionStartIncluding": "16.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*",
"versionEndExcluding": "16.0.5539.1001",
"versionStartIncluding": "16.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-01-26T16:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-807",
"description": "CWE-807: Reliance on Untrusted Inputs in a Security Decision",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-01T13:49:28.047Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Microsoft Office Security Feature Bypass Vulnerability",
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509"
}
],
"title": "Microsoft Office Security Feature Bypass Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2026-21509",
"datePublished": "2026-01-26T17:06:35.512Z",
"dateReserved": "2025-12-30T18:10:54.844Z",
"dateUpdated": "2026-04-01T13:49:28.047Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}