CVE-2026-21514CISA KEV
Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.
- Product
- Office
- Added to KEV
- 10 Feb 2026
- Federal remediation due
- 3 Mar 2026
- Known ransomware use
- Not reported