Executive brief
A security vulnerability in Microsoft Office could allow an attacker to bypass built-in security protections. This issue affects common productivity tools like Word and Excel, potentially allowing unauthorized actions on a user's computer if they are tricked into opening a malicious file. Successful exploitation could lead to a full compromise of the user's data and system access.
Technical details
A security feature bypass vulnerability exists in Microsoft Office (CWE-807) due to the application relying on untrusted inputs when making security-critical decisions. An attacker can exploit this locally by convincing a user to open a specially crafted file, leading to a bypass of intended security restrictions. The vulnerability affects multiple versions of Office, including Microsoft 365 Apps, Office 2016, 2019, and LTSC versions. Microsoft has released security updates to address this issue, and CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later
- Microsoft Microsoft Office 2016 16.0.0 to 16.0.5539.1001
- Microsoft Microsoft Office 2019 19.0.0 to 16.0.10417.20095
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later
Timeline
- 2026-01-26: advisory: Initial publication by Microsoft and NVD
- 2026-01-26: kev added: Added to CISA Known Exploited Vulnerabilities catalog
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
- https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability
- https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability