s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-21509

📛 CVE Title

Microsoft Office Security Feature Bypass Vulnerability

Description

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Overview

State
PUBLISHED
Assigner (CNA)
microsoft
CVSS severity
HIGH
CVSS score
CVSS 7.8 / 10 7.8 7.8 / 10
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Effective score
7.8 / 10 HIGH source: CNA overview
MSRC score
7.8 / 10 HIGH MS rating: Important · Security Feature Bypass
CWE(s)
CWE-807
Reserved
2025-12-30
Published
2026-01-26 08:00 UTC
Last updated
2026-01-29 08:00 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/21xxx/CVE-2026-21509.json
Linked Threat
CVE-2026-21509 — Microsoft Office: Microsoft Office Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerabilities CISA KEV

CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.

Vulnerability name
Microsoft Office Security Feature Bypass Vulnerability
Vendor / project
Microsoft
Product
Office
Date added to KEV
2026-01-26
Remediation due
2026-02-16
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware campaign use
Unknown
CISA notes
Please adhere to Microsoft’s recommended guidelines to address this vulnerability. Implement all final mitigations provided by the vendor for Office 2021, and apply the interim corresponding mitigations for Office 2016 and Office 2019 until the final patch becomes available. For more information please see: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21509
CISA listing
www.cisa.gov/known-exploited-vulnerabilities-catalog

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-01-26 18:16:38 UTC
NVD last modified
2026-02-11 15:40:33 UTC
NVD CVSS v3.1
CVSS 7.8 / 10 7.8 7.8 / 10 HIGH source: secure@microsoft.com
NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability subscore
1.8 / 10
Impact subscore
5.9 / 10
EPSS score
0.1144 (probability of exploitation in next 30 days)
EPSS percentile
93.69% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24

NVD / KEV / EPSS data refreshed 2026-05-25 03:56 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-4666
Assigner
microsoft
Published
Jan 26, 2026, 5:06:35 PM
Updated
Apr 1, 2026, 1:49:28 PM
EUVD base score (CVSS 3.1)
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
EUVD-reported EPSS
15.2900
Vendors
Microsoft
Products
Microsoft Office 2019 (19.0.0 <16.0.10417.20095)
Microsoft Office LTSC 2021 (16.0.1 <https://aka.ms/OfficeSecurityReleases)
Microsoft Office 2016 (-)
Microsoft Office LTSC 2024 (16.0.0 <https://aka.ms/OfficeSecurityReleases)
Microsoft 365 Apps for Enterprise (16.0.1 <https://aka.ms/OfficeSecurityReleases)
Microsoft Office 2016 (16.0.0 <16.0.5539.1001)
Microsoft Office 2019 (-)
Aliases
GHSA-ch84-h92g-mw93

ENISA description: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

EUVD references (1)

Microsoft Security Response Center MSRC

Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-31 03:00 UTC (source: CVRF).

MS severity
Important
Impact
Security Feature Bypass
MS CVSS base score
7.8 / 10 (temporal 7.2)
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Exploit assessment
Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected
Release
2026-Jan
Microsoft remediations / KB articles (7)
  • Click to Run — Vendor Fix / Security Update (fixed build 16.0.10417.20095)
  • https://learn.microsoft.com/en-us/officeupdates/update-history-office-2019 — None Available / Click to Run
  • https://docs.microsoft.com/en-us/officeupdates/office365-proplus-security-updates — None Available / Click to Run
  • 5002713 — Vendor Fix / Security Update (fixed build 16.0.5539.1001)
  • https://support.microsoft.com/help/5002713 — None Available / 5002713
  • <p><a href="https://www.microsoft.com/en-us/msrc/glossary#Mitigation">Mitigation</a> refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of exploitation of a vulnerability.</p> <p><strong>The following mitigating factors might be helpful in your situation:</strong></p> <p>Customers running Microsoft 365 Apps, Office 2021 and later will be <strong>automatically protected</strong> via a service-side change, but will be required to <strong>restart</strong> their Office applications for this to take effect.</p> <p>Customers running Office 2016 and 2019 are not protected until they install the security update. Customers on these versions can apply the <strong>registry keys</strong> described as follows to be immediately protected.</p> <p>Microsoft Office:</p> <ol> <li>To start <strong>blocking</strong> please add the following registry keys:</li> </ol> <p>Caution:  Follow these steps carefully. Serious problems may occur if you modify the registry incorrectly. Before you start we recommend that you have a known good backup of your registry. See this article for more information: <a href="https://support.microsoft.com/en-us/help/322756/how-to-back-up-and-restore-the-registry-in-windows">https://support.microsoft.com/en-us/help/322756/how-to-back-up-and-restore-the-registry-in-windows</a></p> <p>Exit all Microsoft Office applications. Start the Registry Editor by tapping Start (or pressing the Windows key on your keyboard) then typing regedit and pressing enter.</p> <ol start="2"> <li>Locate the <strong>proper registry subkey</strong>. It will be one of the following:</li> </ol> <p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\ (for 64-bit MSI Office, or 32-bit MSI Office on 32-bit Windows)</p> <p>or</p> <p>HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Office\16.0\Common\COM Compatibility\ (for 32-bit MSI Office on 64-bit Windows)</p> <p>or</p> <p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Office\16.0\Common\COM Compatibility\ (for 64-bit Click2Run Office, or 32-bit Click2Run Office on 32-bit Windows)</p> <p>or</p> <p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\WOW6432Node\Microsoft\Office\16.0\Common\COM Compatibility\ (for 32-bit Click2Run Office on 64-bit Windows)</p> <p>Note: The COM Compatibility node may not be present by default. If you don't see it, add it by right-clicking the Common node and choosing Add Key.</p> <ol start="3"> <li>Add a new subkey named {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} by right-clicking the COM Compatibility node and choosing Add Key.</li> </ol> <p>Within that new subkey we're going to add one new value by right-clicking the new subkey and choosing  New &gt; DWORD (32-bit) Value.</p> <p>A REG_DWORD hexadecimal value called Compatibility Flags with a value of 400.</p> <p>Exit Registry Editor and start your Office application.</p> <p><strong>Example</strong></p> <p>For example, in Office 2016, 64-bit, on Windows you would locate this registry key:</p> <p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\</p> <p>Note: Remember, if the COM Compatibility node doesn't exist yet you'll need to create it.</p> <p>Then add a subkey with the name {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}.</p> <p>In this case, the resulting path is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}.</p> <p>To that subkey you'll add a REG_DWORD value called Compatibility Flags with a value of 400.</p> — Mitigation
  • <p><a href="https://www.microsoft.com/en-us/msrc/glossary#Mitigation">Mitigation</a> refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of exploitation of a vulnerability.</p> <p><strong>The following mitigating factors might be helpful in your situation:</strong></p> <p>Customers on Office 2021 and later are automatically protected without registry change. Registry keys do not apply to Office 2016 or Office 2019. Customers using Office 2016 or Office 2019 will not be protected until they install the upcoming security update.</p> — Mitigation
Microsoft FAQ (5)

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

An attacker must send a user a malicious Office file and convince them to open it.

Are the updates for Microsoft Office 2016 and 2019 currently available?

Yes. As of January 26, 2026, the security update for Microsoft Office 2016 and 2019 is available. Customers running Microsoft Office 2016 and 2019 should ensure the update is installed to be protected from this vulnerability.

How do I know what version of Office 2016 and 2019 I am running?

On January 26 2026, Microsoft released build numbers for Office 2016 16.0.5539.1001 and Office 2019 16.0.10417.20095 to address this vulnerability.

To see what version you have installed:

  1. In a document click the File tab.
  2. Click Account in the left hand pane.
  3. Click About . The top line of the About dialog box will display the Build number.

What kind of security feature could be bypassed by successfully exploiting this vulnerability?

This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office which protect users from vulnerable COM/OLE controls.

Is the Preview Pane an attack vector for this vulnerability?

No, the Preview Pane is not an attack vector.

Affected products (5)

VendorProductVersionsPlatforms
Microsoft Microsoft 365 Apps for Enterprise 16.0.1 (affected) 32-bit Systems, x64-based Systems
Microsoft Microsoft Office 2016 16.0.0 (affected) 32-bit Systems, x64-based Systems
Microsoft Microsoft Office 2019 19.0.0 (affected) 32-bit Systems, x64-based Systems
Microsoft Microsoft Office LTSC 2021 16.0.1 (affected) 32-bit Systems, x64-based Systems
Microsoft Microsoft Office LTSC 2024 16.0.0 (affected) 32-bit Systems, x64-based Systems

Affected products — CPE 2.3 (10) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
  • cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
  • cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x64:*
  • cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:*
  • cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x64:*
  • cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x86:*
  • cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*
  • cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*
  • cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*
  • cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (8)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (4)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cwe CWE-807 no local data 2026-05-14 02:58 UTC
cve CVE-2026-21509 no local data 2026-05-14 02:58 UTC

Flagged vendors

    Remediations (9)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2026-21509.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-21509",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-27T13:34:19.867845Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-01-26",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-27T13:34:26.498Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2026-02-10T14:57:48.648Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "platforms": [
                "32-bit Systems",
                "x64-based Systems"
              ],
              "product": "Microsoft 365 Apps for Enterprise",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "https://aka.ms/OfficeSecurityReleases",
                  "status": "affected",
                  "version": "16.0.1",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "32-bit Systems",
                "x64-based Systems"
              ],
              "product": "Microsoft Office 2016",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "16.0.5539.1001",
                  "status": "affected",
                  "version": "16.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "32-bit Systems",
                "x64-based Systems"
              ],
              "product": "Microsoft Office 2019",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "16.0.10417.20095",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "32-bit Systems",
                "x64-based Systems"
              ],
              "product": "Microsoft Office LTSC 2021",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "https://aka.ms/OfficeSecurityReleases",
                  "status": "affected",
                  "version": "16.0.1",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "32-bit Systems",
                "x64-based Systems"
              ],
              "product": "Microsoft Office LTSC 2024",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "https://aka.ms/OfficeSecurityReleases",
                  "status": "affected",
                  "version": "16.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "16.0.10417.20095",
                      "versionStartIncluding": "19.0.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*",
                      "versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
                      "versionStartIncluding": "16.0.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*",
                      "versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
                      "versionStartIncluding": "16.0.1",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*",
                      "versionEndExcluding": "https://aka.ms/OfficeSecurityReleases",
                      "versionStartIncluding": "16.0.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:microsoft:office_2016:*:*:*:*:*:*:x86:*",
                      "versionEndExcluding": "16.0.5539.1001",
                      "versionStartIncluding": "16.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "datePublic": "2026-01-26T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en-US",
              "value": "Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en-US",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-807",
                  "description": "CWE-807: Reliance on Untrusted Inputs in a Security Decision",
                  "lang": "en-US",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-01T13:49:28.047Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "Microsoft Office Security Feature Bypass Vulnerability",
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509"
            }
          ],
          "title": "Microsoft Office Security Feature Bypass Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2026-21509",
        "datePublished": "2026-01-26T17:06:35.512Z",
        "dateReserved": "2025-12-30T18:10:54.844Z",
        "dateUpdated": "2026-04-01T13:49:28.047Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }