CVE-2026-21509CISA KEV
Microsoft Office Security Feature Bypass Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
- Product
- Office
- Added to KEV
- 26 Jan 2026
- Federal remediation due
- 16 Feb 2026
- Known ransomware use
- Not reported