CVE-2026-21509

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

  • Published Jan 26, 2026
  • CVSS 7.8 high
  • 70.8% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

In the news

CVE-2026-21509 at the National Vulnerability Database