Skip to content
Fancy Bear Exploits Microsoft Zero-Day Vulnerability CVE-2026-21509

Fancy Bear Exploits Microsoft Zero-Day Vulnerability CVE-2026-21509

First seen 10 Feb 2026, 16:42 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

The Russian cyber espionage group Fancy Bear, also known as APT28, has initiated Operation Neusploit, exploiting a zero-day vulnerability (CVE-2026-21509) in Microsoft RTF files. This vulnerability allows attackers to execute arbitrary code on victim systems, leading to the deployment of backdoors and email stealers, targeting various organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

Timeline

2026-01-26
CVE-2026-21509 published and added to CISA KEV
2026-01-27
First public PoC for CVE-2026-21509 released
2026-02-10
Fancy Bear launches Operation Neusploit exploiting CVE-2026-21509

More articles in this cluster (3)

Following this threat?

Track Apt28, Microsoft and CVE-2026-21509 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed