Quiverquant Microsoft Word Vulnerability CVE-2026-21514 Exposes Millions to Malware Attacks
Article Content
- •CVE-2026-21514 allows silent malware deployment in Microsoft Word without user warnings.
- •Over 15.5 million assets are exposed, with the U.S. having the highest number at 15.4 million.
- •Rapid7 reports a significant increase in the speed of vulnerability exploitation, necessitating urgent action.
CVE-2026-21514 is a security feature bypass vulnerability in Microsoft Word, disclosed on February 10, 2026. This flaw allows attackers to exploit nearly 14 million assets across seven Tier 1 countries, primarily in the United States. The vulnerability enables malware deployment without triggering user warnings, as it bypasses security prompts. Active exploitation of this vulnerability was confirmed prior to the patch release. Tenable's analysis revealed that over 15.5 million assets are affected, with the U.S. accounting for 15.4 million. The attack method requires user interaction only to open a malicious Word document, after which the exploit executes silently. Organizations are urged to implement exposure management to mitigate risks from advanced persistent threats. Rapid7's 2026 Global Threat Landscape Report indicates a broader trend of rapidly shrinking vulnerability exploitation timelines, emphasizing the need for proactive cybersecurity measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Earth Kurma, Microsoft and CVE-2026-21514 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…