Skip to content
New Microsoft Office Vulnerability Sparks Cyberattacks on Ukraine and EU Institutions

New Microsoft Office Vulnerability Sparks Cyberattacks on Ukraine and EU Institutions

Mezha February 2, 2026

As reported by State Service of Special Communications and Information Protection of Ukraine

CERT-UA has recorded a new wave of targeted cyberattacks using a fresh vulnerability in Microsoft Office, aimed at Ukrainian government bodies and institutions in EU countries. The information is confirmed by the State Service of Special Communications and Information Protection of Ukraine.

According to the State Service, on January 26, 2026 Microsoft reported a dangerous vulnerability in Office applications (CVE-2026-21509). The very day, attackers created a malicious document on the topic of EU consultations regarding Ukraine, exploited this vulnerability, and launched a mass attack on Ukrainian authorities.

“Under the guise of a distribution from the Ukrainian Hydrometeorological Center, they sent malicious emails to more than 60 addresses of ministries and agencies with the file “BULLETEN_H.doc”, which, when opened, gave hackers access to the victim’s computer.”

In CERT-UA they also explained the technical mechanism: opening this document using Microsoft Office leads to establishing a network connection to an external resource via the WebDAV protocol, followed by downloading the file and launching executable code.

Experts recommend immediately installing the updates from Microsoft and/or changing Windows registry settings in accordance with official instructions; it is advisable to limit or carefully verify connections to the Filen cloud storage (filen.io), as the group APT28 uses it to manage threats.

CERT-UA reports that hackers from the group UAC-0001 (APT28) are conducting cyberattacks against Ukraine and EU countries using the CVE-2026-21509 exploit (CERT-UA#19542).

At the end of January 2026, three more documents with a similar exploit were discovered, which, in content and structure of embedded URLs, were used in cyberattacks on EU organizations. There was also a case when the domain name used in the attack on 30.01.2026 was registered on the same day.

Analysts believe that in the near future the number of such attacks may increase due to users’ slow Office package updates or difficulties applying the recommended protections.

Низка держорганів зазнали кібератак – Держспецзв’язку

Extracted Entities

APT Groups (2)

Attack Types (1)

Countries (1)

Industries (1)