CVE-2026-21509
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
- Published Jan 26, 2026
- CVSS 7.8 high
- 70.8% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
Affected software
In the news
- APT and financial attacks on industrial organizations in Q2 2026 Kaspersky ICS CERT ·
- APT and financial attacks on industrial organizations in Q1 2026 Kaspersky ICS CERT ·
- Quantifying 2026 Routinely Targeted Vulnerabilities (So Far) VulnCheck Blog ·
- Sednit reloaded: Back in the trenches WeLiveSecurity ·