CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV)
CVE-2026-21509 (TL-2026-0021), also tracked as Microsoft Office Security Bypass, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-02-02. It is attributed to APT28 (Russia) with medium confidence, affects Microsoft Microsoft Office, references 1 CVE (CVE-2026-21509), maps to 26 MITRE ATT&CK techniques (T1003, T1005, T1027), and is covered by 16 detection rules and 47 indicators of compromise.
Key facts for TL-2026-0021
- Threat ID
- TL-2026-0021
- Also known as
- Microsoft Office Security Bypass
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-02-02
- Last reviewed
- 2026-02-02
- Attribution
- APT28
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- EXPLOITATION
- Target sectors
- Government, Defense, Critical Infrastructure, Financial Services, Healthcare, Education, Energy, Information Technology, Transportation
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 16
- Indicators of compromise
- 47
CVE-2026-21509 is a Microsoft Office Security Feature Bypass vulnerability actively exploited in the wild and added to the CISA Known Exploited Vulnerabilities (KEV) catalog on January 26, 2026 with a mandatory federal remediation deadline of February 16, 2026. The vulnerability exploits a 'reliance on untrusted inputs in a security decision' flaw in Microsoft Office's OLE (Object Linking and Embedding) security model, allowing an unauthorized attacker to bypass Protected View, Mark-of-the-Web (MOTW), and other Office security features locally. This is the CISA KEV enforcement perspective on the OLE bypass lineage — a 30+ year attack surface that has produced 6 generations of security feature bypass vulnerabilities. Under BOD 22-01, all Federal Civilian Executive Branch (FCEB) agencies must remediate or remove affected systems by the deadline. CISA notes some impacted products are End-of-Life (EoL) or End-of-Service (EoS), advising discontinuation. The CVSS v3.1 base score is 7.8 (HIGH) with local attack vector, low complexity, no privileges required, but requiring user interaction (opening a crafted document). EPSS score of 0.13 (13% probability of exploitation in next 30 days — significantly elevated). Affected products span the entire Microsoft Office ecosystem: Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft 365 Apps for Enterprise. The vulnerability is classified as CWE-807 (Reliance on Untrusted Inputs in a Security Decision) — Office trusts document metadata/properties that an attacker can manipulate to bypass security checks. Active exploitation confirmed by CISA but ransomware campaign usage unknown at this time. This threat represents the federal compliance enforcement dimension of the OLE eternal attack surface.
How CVE-2026-21509 works
CVE-2026-21509 exploits a fundamental design flaw in Microsoft Office's security decision framework: the OLE subsystem relies on untrusted inputs (document metadata, zone identifiers, embedded object properties) to make security decisions about whether to enable Protected View, apply MOTW restrictions, or allow macro execution. An attacker crafts a malicious Office document that manipulates these trusted-but-manipulable inputs to bypass security features that should prevent code execution from untrusted documents.
The attack chain: (1) Attacker crafts a malicious Office document (Word, Excel, PowerPoint) with manipulated OLE properties/metadata that trick Office's security decision engine, (2) Document is delivered via spearphishing email, web download, or file share, (3) Victim opens the document — because security inputs are manipulated, Office does NOT apply Protected View or MOTW restrictions, (4) Document opens in full editing mode with active content enabled, bypassing the security dialog that normally warns users, (5) Embedded macros, OLE objects, or active content execute without user approval, achieving arbitrary code execution.
CISA KEV Enforcement Context: Under Binding Operational Directive (BOD) 22-01, issued November 3, 2021, all Federal Civilian Executive Branch (FCEB) agencies are compelled to remediate KEV catalog vulnerabilities within CISA's specified timeline. CVE-2026-21509 was added January 26, 2026 with a 21-day remediation window (due February 16, 2026). This is a mandatory, legally binding requirement — not a recommendation. Agencies that cannot patch must remove affected assets from their network. CISA does not issue waivers or exceptions.
BOD 22-01 Key Requirements: (1) Federal agencies must review and update internal vulnerability management procedures within 60 days, (2) Remediate each KEV vulnerability within the CISA-specified timeframe, (3) Report status of remediation to CISA, (4) If patching is impossible, remove the asset from the network — isolation is an acceptable form of removal, (5) For third-party hosted systems, agencies must contact service providers for compliance status.
The OLE Lineage (6 Generations of Bypass): This vulnerability is the latest in a persistent lineage of OLE-related security feature bypasses in Microsoft Office spanning 30+ years: Gen 1 (OLE1, 1990s) — original Object Linking and Embedding with no security model, Gen 2 (OLE2/COM, 2000s) — macro viruses exploited unlimited OLE capabilities, Gen 3 (Protected View era, 2010s) — Microsoft added sandboxing but OLE objects could escape, Gen 4 (MOTW era, mid-2010s) — Mark-of-the-Web added zone identifiers but OLE manipulation bypassed them, Gen 5 (recent CVEs) — repeated bypasses of Protected View via OLE property manipulation, Gen 6 (CVE-2026-21509) — current KEV-listed active exploitation of untrusted input reliance in security decisions.
Critical Infrastructure Impact: Microsoft Office is deployed across virtually every federal agency, defense contractor, critical infrastructure operator, and enterprise worldwide. The February 16 deadline creates acute pressure on organizations with large, complex Office deployments. End-of-Life versions (Office 2016) are explicitly called out by CISA — agencies running EoL Office must discontinue use entirely, not just patch. This is a forcing function for Office modernization across the federal enterprise.
The paradox: Office's security features (Protected View, MOTW, macro blocking) are supposed to protect users from malicious documents. CVE-2026-21509 bypasses ALL of them by manipulating the inputs Office uses to decide whether to apply those protections. The security decision itself is the vulnerability.
MITRE ATT&CK techniques used in TL-2026-0021
credential-access
collection
T1005 Data from Local System; T1056 Input Capture
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1218 System Binary Proxy Execution
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution; T1204.002 Malicious File; T1559 Inter-Process Communication
command-and-control
T1071 Application Layer Protocol
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
defense-impairment
T1112 Modify Registry; T1553 Subvert Trust Controls
persistence
T1137 Office Application Startup
initial-access
T1199 Trusted Relationship; T1566 Phishing; T1566.001 Spearphishing Attachment
impact
T1486 Data Encrypted for Impact
lateral-movement
resource-development
reconnaissance
Affected products and versions in CVE-2026-21509
- Microsoft — Microsoft Office
Vulnerable versions: Multiple versions including EoL
Fixed in: See Microsoft advisory
Remediation for CVE-2026-21509
Patches
- Microsoft January 2026 Patch Tuesday — Security Update for Microsoft Office (all affected versions)
- KB articles available via Microsoft Update Catalog for each affected product
Immediate actions
- Apply January 2026 Microsoft Office security update immediately — KEV deadline February 16, 2026
- For Office 2016 (EoL): CISA advises discontinuing use and transitioning to a supported version
- If patching is impossible within the deadline, remove affected systems from the network per BOD 22-01
- Block Office document attachments at email gateway until patching is confirmed
- Enable Attack Surface Reduction (ASR) rules in Microsoft Defender: Block Office applications from creating child processes, Block Office applications from creating executable content, Block Win32 API calls from Office macros
- Verify Protected View is enabled (should be enabled by default but verify it hasn't been disabled via GPO)
- Enable MOTW enforcement via Group Policy: User Configuration → Administrative Templates → Microsoft Office → Security Settings
Workarounds
- Enable Application Guard for Office (Microsoft Defender Application Guard) — opens untrusted documents in isolated Hyper-V container
- Block OLE object embedding via Group Policy: User Configuration → Administrative Templates → Microsoft Office → Security → Block OLE object activation
- Disable active content in documents from untrusted sources via Office Trust Center settings
- Use ASR rules to prevent Office from creating child processes and executable content
- Network isolation of unpatched systems (acceptable under BOD 22-01 as form of removal)
Longer-term hardening
- Migrate all Office 2016 deployments to supported versions (Office LTSC 2024 or Microsoft 365 Apps)
- Implement Zero Trust document handling: all external documents open in Application Guard (MDAG)
- Deploy Microsoft Defender for Office 365 with Safe Documents feature for Protected View exits
- Implement continuous KEV monitoring via CDM dashboard or automated KEV feed integration
- Subscribe to CISA KEV catalog updates (GovDelivery) for immediate notification of new additions
- Deploy document sandboxing solutions for high-risk environments (defense, critical infrastructure)
- Implement quarterly OLE/COM attack surface audits — review registry keys, file type associations, and embedded object policies
- Consider Microsoft 365 Apps cloud-managed deployment for automatic security updates
CVEs associated with CVE-2026-21509
Weaknesses (CWE) in CVE-2026-21509
CWE-807
Timeline of CVE-2026-21509
- Microsoft introduces OLE 1.0 (Object Linking and Embedding) in Windows 3.0 — the beginning of 30+ years of document-embedded object security challenges. No security model exists. Source: Microsoft COM documentation
- Microsoft releases OLE 2.0 based on Component Object Model (COM). Enables rich embedding of objects across applications but creates massive attack surface for macro viruses and embedded object exploitation. Source: Microsoft OLE/COM history
- Microsoft introduces Protected View in Office 2010 — a read-only sandbox for documents from untrusted sources. First major security boundary for OLE documents. Attackers immediately begin seeking bypasses. Source: Microsoft Office security documentation
- Mark-of-the-Web (MOTW) enforcement strengthened in Office 2016. Zone identifier (Zone.Identifier ADS) used as security input to trigger Protected View. OLE manipulation techniques discovered to bypass MOTW. Source: Microsoft Office security model
- CISA issues Binding Operational Directive 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities. Establishes KEV catalog and mandatory remediation timelines for all Federal Civilian Executive Branch (FCEB) agencies. 44 U.S.C. § 3553(b)(2). Source: https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities
- Microsoft begins blocking macros by default in Office documents from the internet (MOTW-tagged). Significant security improvement but OLE object embedding and security feature bypass techniques remain viable attack vectors. Source: Microsoft Security Blog
- Multiple CVEs in 2024 demonstrate ongoing OLE security feature bypass capability. Protected View, MOTW, and macro blocking repeatedly circumvented via OLE property manipulation, zone identifier spoofing, and embedded object techniques. 6th generation of OLE bypass attacks. Source: MSRC Security Update Guides 2024
- Microsoft January 2026 Patch Tuesday releases security update for CVE-2026-21509. Classified as Security Feature Bypass, CVSS 7.8 HIGH. Fixes reliance on untrusted inputs in security decision within Office OLE subsystem. Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
- Discovered
- First Exploitation
- NVD publishes CVE-2026-21509 with CVSS v3.1 base score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Attack vector local, complexity low, no privileges required, user interaction required. Full CIA impact. Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21509
- CISA adds CVE-2026-21509 to Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation in the wild. KEV addition date: January 26, 2026. Remediation deadline: February 16, 2026 (21 days). CISA notes some impacted products are EoL/EoS — advises discontinuation. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509
- Disclosed
- Vicarius vSociety publishes detection and mitigation scripts for CVE-2026-21509, demonstrating community urgency around the vulnerability. Third-party tooling available for identification and remediation verification. Source: https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability
- CISA adds 4 additional Microsoft vulnerabilities to KEV catalog on the same day — CVE-2026-21514 (Office Word untrusted input), CVE-2026-21519 (Windows DWM type confusion), CVE-2026-21533 (RDP privilege management), CVE-2026-21510 (Windows Shell protection failure). Demonstrates sustained campaign against Microsoft products. Due date March 3, 2026. Source: CISA KEV Catalog
- NVD record for CVE-2026-21509 updated with additional references and metadata. CISA-ADP adds government resource tag. Concurrent with February 2026 Patch Tuesday which adds 4 more Office/Windows KEVs (CVE-2026-21514, CVE-2026-21519, CVE-2026-21533, CVE-2026-21510). Source: NVD
- FIRST EPSS score for CVE-2026-21509 at 0.13006 (13% exploitation probability in next 30 days) — significantly elevated above baseline. Confirms active exploitation aligns with CISA KEV classification. Tenable classifies as 'Vulnerability of Interest.' Source: https://www.first.org/epss/
- MANDATORY REMEDIATION DEADLINE for CVE-2026-21509 under BOD 22-01. All FCEB agencies must have applied the January 2026 security update OR removed affected systems from their network by this date. Non-compliance reportable to CISA. No waivers or exceptions available. Source: CISA BOD 22-01
- As of 2026-05-29, CVE-2026-21509 (Office OLE/MOTW bypass) is patched but remains under active, multi-actor exploitation: Proofpoint reports attempts ongoing into mid-May 2026 and VulnCheck lists it as routinely targeted. Now attributed (record says "Unattributed") to APT28/TA422 (Operation Neusploit), DPRK TA406, and Razor Tiger; still in CISA KEV, ransomware use Unknown.
Sources cited for CVE-2026-21509
- CISA KEV Catalog Entry
- Microsoft Security Response Center
- CISA KEV Catalog — CVE-2026-21509
- NVD — CVE-2026-21509
- CISA BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities
- Tenable — CVE-2026-21509 Vulnerability of Interest
- AttackerKB — CVE-2026-21509
- Vicarius — CVE-2026-21509 Detection Script
- Vicarius — CVE-2026-21509 Mitigation Script
- CISA KEV Full Catalog (JSON Feed)
- CISA KEV Full Catalog (CSV)
- CVE-2026-21514 — Microsoft Office Word Untrusted Input (Same Patch Tuesday)
- CVE-2026-21510 — Microsoft Windows Shell Protection Mechanism Failure (Sibling KEV)
- Microsoft OLE Documentation — Component Object Model
- MITRE ATT&CK — Phishing: Spearphishing Attachment (T1566.001)
Threats related to CVE-2026-21509
- Pawn Storm (APT28) Deploys PRISMEX Malware Suite via CVE-2026-21509 and CVE-2026-21513 Zero-Days Targeting Ukrainian Defense Supply Chain
- APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage Campaign (CVE-2026-21509)
- APT28 PixyNetLoader — Loader Evolution 2024–2026 (Operation Neusploit, CVE-2026-21509)
- Microsoft Office Zero-Day CVE-2026-21509: OLE Security Bypass Under Active Exploitation
- APT28 Operation Neusploit: MS Office CVE-2026-21509 Espionage Campaign
- CVE-2026-21509: Russian Hackers Exploit Microsoft Office Vulnerability Against Ukraine
Detection coverage for TL-2026-0021
As of 2026-02-02, Threadlinqs Intelligence publishes 16 detection rule(s) for TL-2026-0021 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.