Skip to content
Microsoft Office Zero-Day Vulnerability Exploited

Microsoft Office Zero-Day Vulnerability Exploited

First seen 29 Jan 2026, 22:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

On January 26, 2026, Microsoft released emergency out-of-band security updates to address CVE-2026-21509, a zero-day security feature bypass vulnerability in Microsoft Office. The flaw, rated 'Important' with a CVSS v3.1 base score of 7.8, allows attackers to exploit untrusted inputs in security decisions, circumventing OLE mitigations for vulnerable COM/OLE controls.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track CVE-2026-21509 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed