LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-21509: Microsoft Office Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 26, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 16, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-21509 to its Known Exploited Vulnerabilities catalog on Jan 26, 2026, with a federal patch deadline of Feb 16, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a…

Microsoft Office contains a security feature bypass vulnerability that stems from reliance on untrusted inputs when making a security decision. An attacker with local access can circumvent a protection mechanism that the application should enforce.

How it works

The weakness is classified as CWE-807. The affected code path accepts input that should not be trusted for an access-control or integrity check and proceeds to act on that input. Because the decision occurs locally, an attacker who can supply or influence the input on the same system can cause the security feature to be skipped.

Am I affected? How to find it in your systems

Inventory all installations of Microsoft Office, including desktop applications and any integrated components that run on endpoints or servers. Confirm the exact versions and configurations against the vendor advisory, because some impacted releases may already be end-of-life or end-of-service. Review software-asset records, endpoint-management consoles, and configuration-management databases for any Office deployments that have not been updated to a supported branch.

How to remediate

Apply the vendor-supplied update referenced in the advisory. Where a patch is unavailable because a product has reached end-of-life or end-of-service, discontinue use and migrate to a supported version. Follow any additional configuration guidance published by the vendor for the affected components.

If you can't patch immediately

Apply mitigations exactly as described in the vendor instructions. For cloud-hosted services, adhere to applicable BOD 22-01 requirements. Where mitigations cannot be implemented, remove or isolate the affected Office installations until they can be replaced or updated. Monitor for local attempts to invoke the bypassed security feature through existing endpoint-detection rules.

If your data may have been exposed

Actively exploited instances of this class of vulnerability have led to unauthorized access. Organizations can run a free exposure scan of their domains against known breach data to determine whether related credentials or documents have already appeared in public repositories.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-807
Added to CISA KEVJan 26, 2026
Federal patch deadlineFeb 16, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities