Microsoft Office Zero-Day CVE-2026-21509: OLE Security Bypass Under Active Exploitation

Microsoft Office Zero-Day CVE-2026-21509 (TL-2026-0010), also tracked as MS Office OLE Bypass, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-02-02. It has no confirmed attribution, affects Microsoft Microsoft Office, references 1 CVE (CVE-2026-21509), maps to 31 MITRE ATT&CK techniques (T1003, T1005, T1027), and is covered by 31 detection rules and 64 indicators of compromise.

Key facts for TL-2026-0010

Threat ID
TL-2026-0010
Also known as
MS Office OLE Bypass
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
2026-02-02
Last reviewed
2026-02-02
Attribution confidence
NONE
Motivation
Exploitation
Target sectors
Government, Defense, Financial Services, Healthcare, Energy, Education, Technology, Legal, Media, Manufacturing
Target regions
Global
Detection rules
31
Indicators of compromise
64

CVE-2026-21509 is a high-severity (CVSS 7.8) security feature bypass vulnerability in Microsoft Office that is under active exploitation in the wild. The vulnerability exists in how Microsoft Office handles OLE (Object Linking and Embedding) objects — specifically, a flaw where reliance on untrusted inputs in a security decision allows an attacker to bypass OLE security checks that normally prevent embedded objects from executing malicious content. When a victim opens a specially crafted Office document (Word, Excel, PowerPoint, or Outlook attachment), the embedded OLE object bypasses Protected View, Mark-of-the-Web (MOTW) propagation, and OLE activation prompts, enabling code execution in the context of the current user without the expected security warnings. Added to CISA KEV on January 26, 2026 with a remediation deadline of February 16, 2026. Affects Microsoft Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft 365 Apps for Enterprise. Some affected products may be end-of-life (EoL). Patched in Microsoft's January 2026 Patch Tuesday release.

How Microsoft Office Zero-Day CVE-2026-21509 works

CVE-2026-21509 exploits a fundamental weakness in how Microsoft Office evaluates trust decisions for embedded OLE objects. OLE (Object Linking and Embedding) is a decades-old Microsoft technology that allows documents to contain embedded objects from other applications — an Excel spreadsheet inside a Word document, a PowerPoint slide inside an email, or more dangerously, executable content like scripts, ActiveX controls, or linked files.

Microsoft Office implements multiple security layers to protect users from malicious OLE objects: Protected View (read-only sandbox for files from untrusted sources), Mark-of-the-Web (MOTW — Zone.Identifier alternate data stream marking files downloaded from the internet), OLE activation prompts (user confirmation before executing embedded objects), and macro security policies. CVE-2026-21509 bypasses one or more of these security layers by exploiting a flaw where the security decision relies on untrusted input — specifically, metadata or properties within the OLE object itself that the attacker controls.

**Attack Vector:** The attack requires user interaction — the victim must open a specially crafted Office document. The document is typically delivered via spearphishing email attachment, download link, file share, or collaboration platform. Once opened, the malicious OLE object exploits the security feature bypass to execute without triggering the expected security prompts. The attack is local (AV:L) — the attacker does not need network access to the target, but needs the victim to open the document.

**Impact:** With CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), successful exploitation grants the attacker code execution in the context of the current user. Since most enterprise users run with standard user privileges but have access to sensitive data, documents, email, and internal network resources, this effectively provides: access to all files the user can read/write, ability to install malware or establish persistence, credential harvesting from memory or cached credentials, lateral movement to internal resources, and data exfiltration.

**Historical Context:** OLE security bypasses are a recurring pattern in Microsoft Office exploitation. Notable predecessors include: CVE-2021-40444 (MSHTML OLE object loading remote HTML/ActiveX), CVE-2022-30190 (Follina — ms-msdt: protocol handler via OLE), CVE-2023-36884 (Office HTML RCE via MOTW bypass), CVE-2024-21413 (Outlook OLE preview bypass via file:// protocol), and CVE-2024-38200 (Office NTLM credential leak via OLE). Each generation finds new ways to bypass the security layers Microsoft adds. CVE-2026-21509 continues this pattern.

**Active Exploitation:** CISA added CVE-2026-21509 to the Known Exploited Vulnerabilities (KEV) catalog on January 26, 2026, confirming active exploitation in the wild. The BOD 22-01 remediation deadline is February 16, 2026. While specific campaign details have not been publicly attributed, the CISA KEV listing and Tenable's 'Vulnerability of Interest' classification confirm this is not theoretical. The EPSS score of 0.13006 (top ~13% of all CVEs) indicates meaningful exploitation probability.

**Affected Products:** Microsoft Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft 365 Apps for Enterprise. CISA notes some affected products may be end-of-life — Office 2016 mainstream support ended in 2020 and extended support ended in 2025. Organizations still running Office 2016 are advised to discontinue use.

**Patch:** Microsoft released a security update as part of the January 2026 Patch Tuesday (January 26, 2026). The patch addresses the untrusted input validation in OLE object security decisions. Organizations should apply the update immediately given active exploitation and the CISA KEV deadline.

MITRE ATT&CK techniques used in TL-2026-0010

credential-access

T1003 OS Credential Dumping; T1187 Forced Authentication

collection

T1005 Data from Local System; T1074 Data Staged; T1114 Email Collection

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1221 Template Injection

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

discovery

T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution; T1204 User Execution; T1559 Inter-Process Communication

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

defense-impairment

T1112 Modify Registry; T1553 Subvert Trust Controls

persistence

T1137 Office Application Startup

initial-access

T1195 Supply Chain Compromise; T1566 Phishing

lateral-movement

T1534 Internal Spearphishing

resource-development

T1587 Develop Capabilities; T1608 Stage Capabilities

Affected products and versions in Microsoft Office Zero-Day CVE-2026-21509

  • Microsoft — Microsoft Office
    Vulnerable versions: Office 2016; Office 2019; Office 2021; Microsoft 365
    Fixed in: Office 2016: 16.0.5539.1001; Office 2019: 16.0.10417.20095; Office 2021+: Service-side update

Remediation for Microsoft Office Zero-Day CVE-2026-21509

Patches

  • Microsoft January 2026 Patch Tuesday: Security update for Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft 365 Apps for Enterprise

Immediate actions

  • Apply the January 2026 Patch Tuesday security update for Microsoft Office immediately — CISA KEV deadline is February 16, 2026
  • If running Office 2016 (end-of-life), upgrade to a supported Office version (Office LTSC 2024 or Microsoft 365 Apps)
  • Enable Protected View for all file origins: File → Options → Trust Center → Trust Center Settings → Protected View → check all three options
  • Block OLE object activation in documents from the internet via Group Policy: User Configuration → Administrative Templates → Microsoft Office → Security → Block activation of OLE objects from the internet
  • Ensure Attack Surface Reduction (ASR) rules are enabled in Microsoft Defender: 'Block Office applications from creating child processes' and 'Block Office applications from injecting code into other processes'

Workarounds

  • If unable to patch immediately: Open suspicious documents only in Protected View and do not click 'Enable Editing'
  • Use Office Online (web versions) for opening untrusted documents — web versions have reduced OLE object support and do not execute embedded content
  • Configure email gateway to strip or quarantine Office documents with embedded OLE objects from external senders
  • Set registry key to disable OLE object activation: HKCU\Software\Microsoft\Office\[version]\Common\Security\DisableOLEObjectCreation = 1

Longer-term hardening

  • Implement application whitelisting (Windows Defender Application Control / AppLocker) to prevent unauthorized executables launched via OLE objects
  • Deploy Microsoft Defender for Office 365 Safe Attachments policy to detonate attachments in sandbox before delivery
  • Configure Conditional Access policies to restrict Office document access from unmanaged devices
  • Implement Office Cloud Policy Service to centrally manage Trust Center settings across the organization
  • Deploy data loss prevention (DLP) rules to flag Office documents with embedded OLE objects from external sources
  • Conduct user awareness training on document-borne threats — OLE objects, macros, embedded content

CVEs associated with Microsoft Office Zero-Day CVE-2026-21509

CVE-2026-21509

Weaknesses (CWE) in Microsoft Office Zero-Day CVE-2026-21509

CWE-863, CWE-20

Timeline of Microsoft Office Zero-Day CVE-2026-21509

  • NVD publishes CVE-2026-21509 entry. Classified as security feature bypass — reliance on untrusted inputs in security decision allows unauthorized attacker to bypass security feature locally. Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21509
  • Microsoft releases January 2026 Patch Tuesday security updates. CVE-2026-21509 (Microsoft Office Security Feature Bypass) disclosed and patched. CVSS 7.8 High. Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
  • Tenable classifies CVE-2026-21509 as 'Vulnerability of Interest' with EPSS 0.13006. CVSS v2: 7.2, CVSS v3: 7.8. Source: https://www.tenable.com/cve/CVE-2026-21509
  • Active exploitation in the wild confirmed by CISA KEV listing. Specific campaigns and threat actors not publicly attributed at this time. The combination of CISA KEV day-zero addition and CVSS 7.8 indicates high-confidence exploitation.
  • CVE-2026-21509 published by Microsoft Corporation. CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Described as 'Microsoft Office Security Feature Bypass Vulnerability' — reliance on untrusted inputs in a security decision allows unauthorized attacker to bypass security feature locally. Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21509
  • Microsoft releases January 2026 Patch Tuesday security updates. CVE-2026-21509 patched across Office 2016, 2019, LTSC 2021, LTSC 2024, and Microsoft 365 Apps. Part of a large update addressing multiple zero-days. Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
  • CISA adds CVE-2026-21509 to Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. BOD 22-01 remediation deadline set to February 16, 2026. Ransomware usage: Unknown. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509
  • Vicarius vSociety publishes detection and mitigation scripts for CVE-2026-21509. Community-contributed tooling for identifying and remediating affected Office installations. Source: https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability
  • Vicarius publishes detection and mitigation scripts for CVE-2026-21509 on vSociety platform. Provides automated scanning and remediation tooling. Source: https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability
  • NVD updates CVE-2026-21509 entry with additional references and metadata. Six change records tracked. Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21509
  • Microsoft February 2026 Patch Tuesday releases addressing 54 CVEs including 6 zero-days. January CVEs including CVE-2026-21509 remain under active exploitation for organizations that haven't patched. Source: https://www.tenable.com/blog/microsofts-february-2026-patch-tuesday-addresses-54-cves-cve-2026-21510-cve-2026-21513
  • CISA BOD 22-01 remediation deadline for CVE-2026-21509. All federal civilian executive branch (FCEB) agencies required to have applied mitigations by this date. Non-federal organizations strongly encouraged to meet this deadline.
  • CISA BOD 22-01 remediation deadline for CVE-2026-21509. Federal agencies and BOD-covered entities must have applied patches or mitigations by this date. Organizations outside federal scope should treat this as a critical deadline.
  • As of 2026-05-29, CVE-2026-21509 is patched (Microsoft OOB fix Jan 26, 2026; CISA KEV deadline Feb 16) but remains under active in-the-wild exploitation against unpatched Office. Per VulnCheck (May 2026) it is "routinely targeted": APT28/TA422 weaponized it in Jan, and DPRK TA406 chained it with CVE-2026-21510 in March-April 2026 campaigns.

Sources cited for Microsoft Office Zero-Day CVE-2026-21509

Threats related to Microsoft Office Zero-Day CVE-2026-21509

Detection coverage for TL-2026-0010

As of 2026-02-02, Threadlinqs Intelligence publishes 31 detection rule(s) for TL-2026-0010 across Splunk SPL, Microsoft KQL and Sigma, covering 64 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats