CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV)

CVE-2026-21509 (TL-2026-0021), also tracked as Microsoft Office Security Bypass, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-02-02. It is attributed to APT28 (Russia) with medium confidence, affects Microsoft Microsoft Office, references 1 CVE (CVE-2026-21509), maps to 26 MITRE ATT&CK techniques (T1003, T1005, T1027), and is covered by 16 detection rules and 47 indicators of compromise.

Key facts for TL-2026-0021

Threat ID
TL-2026-0021
Also known as
Microsoft Office Security Bypass
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-02-02
Last reviewed
2026-02-02
Attribution
APT28
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
EXPLOITATION
Target sectors
Government, Defense, Critical Infrastructure, Financial Services, Healthcare, Education, Energy, Information Technology, Transportation
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
16
Indicators of compromise
47

CVE-2026-21509 is a Microsoft Office Security Feature Bypass vulnerability actively exploited in the wild and added to the CISA Known Exploited Vulnerabilities (KEV) catalog on January 26, 2026 with a mandatory federal remediation deadline of February 16, 2026. The vulnerability exploits a 'reliance on untrusted inputs in a security decision' flaw in Microsoft Office's OLE (Object Linking and Embedding) security model, allowing an unauthorized attacker to bypass Protected View, Mark-of-the-Web (MOTW), and other Office security features locally. This is the CISA KEV enforcement perspective on the OLE bypass lineage — a 30+ year attack surface that has produced 6 generations of security feature bypass vulnerabilities. Under BOD 22-01, all Federal Civilian Executive Branch (FCEB) agencies must remediate or remove affected systems by the deadline. CISA notes some impacted products are End-of-Life (EoL) or End-of-Service (EoS), advising discontinuation. The CVSS v3.1 base score is 7.8 (HIGH) with local attack vector, low complexity, no privileges required, but requiring user interaction (opening a crafted document). EPSS score of 0.13 (13% probability of exploitation in next 30 days — significantly elevated). Affected products span the entire Microsoft Office ecosystem: Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft 365 Apps for Enterprise. The vulnerability is classified as CWE-807 (Reliance on Untrusted Inputs in a Security Decision) — Office trusts document metadata/properties that an attacker can manipulate to bypass security checks. Active exploitation confirmed by CISA but ransomware campaign usage unknown at this time. This threat represents the federal compliance enforcement dimension of the OLE eternal attack surface.

How CVE-2026-21509 works

CVE-2026-21509 exploits a fundamental design flaw in Microsoft Office's security decision framework: the OLE subsystem relies on untrusted inputs (document metadata, zone identifiers, embedded object properties) to make security decisions about whether to enable Protected View, apply MOTW restrictions, or allow macro execution. An attacker crafts a malicious Office document that manipulates these trusted-but-manipulable inputs to bypass security features that should prevent code execution from untrusted documents.

The attack chain: (1) Attacker crafts a malicious Office document (Word, Excel, PowerPoint) with manipulated OLE properties/metadata that trick Office's security decision engine, (2) Document is delivered via spearphishing email, web download, or file share, (3) Victim opens the document — because security inputs are manipulated, Office does NOT apply Protected View or MOTW restrictions, (4) Document opens in full editing mode with active content enabled, bypassing the security dialog that normally warns users, (5) Embedded macros, OLE objects, or active content execute without user approval, achieving arbitrary code execution.

CISA KEV Enforcement Context: Under Binding Operational Directive (BOD) 22-01, issued November 3, 2021, all Federal Civilian Executive Branch (FCEB) agencies are compelled to remediate KEV catalog vulnerabilities within CISA's specified timeline. CVE-2026-21509 was added January 26, 2026 with a 21-day remediation window (due February 16, 2026). This is a mandatory, legally binding requirement — not a recommendation. Agencies that cannot patch must remove affected assets from their network. CISA does not issue waivers or exceptions.

BOD 22-01 Key Requirements: (1) Federal agencies must review and update internal vulnerability management procedures within 60 days, (2) Remediate each KEV vulnerability within the CISA-specified timeframe, (3) Report status of remediation to CISA, (4) If patching is impossible, remove the asset from the network — isolation is an acceptable form of removal, (5) For third-party hosted systems, agencies must contact service providers for compliance status.

The OLE Lineage (6 Generations of Bypass): This vulnerability is the latest in a persistent lineage of OLE-related security feature bypasses in Microsoft Office spanning 30+ years: Gen 1 (OLE1, 1990s) — original Object Linking and Embedding with no security model, Gen 2 (OLE2/COM, 2000s) — macro viruses exploited unlimited OLE capabilities, Gen 3 (Protected View era, 2010s) — Microsoft added sandboxing but OLE objects could escape, Gen 4 (MOTW era, mid-2010s) — Mark-of-the-Web added zone identifiers but OLE manipulation bypassed them, Gen 5 (recent CVEs) — repeated bypasses of Protected View via OLE property manipulation, Gen 6 (CVE-2026-21509) — current KEV-listed active exploitation of untrusted input reliance in security decisions.

Critical Infrastructure Impact: Microsoft Office is deployed across virtually every federal agency, defense contractor, critical infrastructure operator, and enterprise worldwide. The February 16 deadline creates acute pressure on organizations with large, complex Office deployments. End-of-Life versions (Office 2016) are explicitly called out by CISA — agencies running EoL Office must discontinue use entirely, not just patch. This is a forcing function for Office modernization across the federal enterprise.

The paradox: Office's security features (Protected View, MOTW, macro blocking) are supposed to protect users from malicious documents. CVE-2026-21509 bypasses ALL of them by manipulating the inputs Office uses to decide whether to apply those protections. The security decision itself is the vulnerability.

MITRE ATT&CK techniques used in TL-2026-0021

credential-access

T1003 OS Credential Dumping

collection

T1005 Data from Local System; T1056 Input Capture

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1218 System Binary Proxy Execution

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution; T1204.002 Malicious File; T1559 Inter-Process Communication

command-and-control

T1071 Application Layer Protocol

discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

defense-impairment

T1112 Modify Registry; T1553 Subvert Trust Controls

persistence

T1137 Office Application Startup

initial-access

T1199 Trusted Relationship; T1566 Phishing; T1566.001 Spearphishing Attachment

impact

T1486 Data Encrypted for Impact

lateral-movement

T1534 Internal Spearphishing

resource-development

T1587 Develop Capabilities

reconnaissance

T1591 Gather Victim Org Information

Affected products and versions in CVE-2026-21509

  • Microsoft — Microsoft Office
    Vulnerable versions: Multiple versions including EoL
    Fixed in: See Microsoft advisory

Remediation for CVE-2026-21509

Patches

  • Microsoft January 2026 Patch Tuesday — Security Update for Microsoft Office (all affected versions)
  • KB articles available via Microsoft Update Catalog for each affected product

Immediate actions

  • Apply January 2026 Microsoft Office security update immediately — KEV deadline February 16, 2026
  • For Office 2016 (EoL): CISA advises discontinuing use and transitioning to a supported version
  • If patching is impossible within the deadline, remove affected systems from the network per BOD 22-01
  • Block Office document attachments at email gateway until patching is confirmed
  • Enable Attack Surface Reduction (ASR) rules in Microsoft Defender: Block Office applications from creating child processes, Block Office applications from creating executable content, Block Win32 API calls from Office macros
  • Verify Protected View is enabled (should be enabled by default but verify it hasn't been disabled via GPO)
  • Enable MOTW enforcement via Group Policy: User Configuration → Administrative Templates → Microsoft Office → Security Settings

Workarounds

  • Enable Application Guard for Office (Microsoft Defender Application Guard) — opens untrusted documents in isolated Hyper-V container
  • Block OLE object embedding via Group Policy: User Configuration → Administrative Templates → Microsoft Office → Security → Block OLE object activation
  • Disable active content in documents from untrusted sources via Office Trust Center settings
  • Use ASR rules to prevent Office from creating child processes and executable content
  • Network isolation of unpatched systems (acceptable under BOD 22-01 as form of removal)

Longer-term hardening

  • Migrate all Office 2016 deployments to supported versions (Office LTSC 2024 or Microsoft 365 Apps)
  • Implement Zero Trust document handling: all external documents open in Application Guard (MDAG)
  • Deploy Microsoft Defender for Office 365 with Safe Documents feature for Protected View exits
  • Implement continuous KEV monitoring via CDM dashboard or automated KEV feed integration
  • Subscribe to CISA KEV catalog updates (GovDelivery) for immediate notification of new additions
  • Deploy document sandboxing solutions for high-risk environments (defense, critical infrastructure)
  • Implement quarterly OLE/COM attack surface audits — review registry keys, file type associations, and embedded object policies
  • Consider Microsoft 365 Apps cloud-managed deployment for automatic security updates

CVEs associated with CVE-2026-21509

CVE-2026-21509

Weaknesses (CWE) in CVE-2026-21509

CWE-807

Timeline of CVE-2026-21509

  • Microsoft introduces OLE 1.0 (Object Linking and Embedding) in Windows 3.0 — the beginning of 30+ years of document-embedded object security challenges. No security model exists. Source: Microsoft COM documentation
  • Microsoft releases OLE 2.0 based on Component Object Model (COM). Enables rich embedding of objects across applications but creates massive attack surface for macro viruses and embedded object exploitation. Source: Microsoft OLE/COM history
  • Microsoft introduces Protected View in Office 2010 — a read-only sandbox for documents from untrusted sources. First major security boundary for OLE documents. Attackers immediately begin seeking bypasses. Source: Microsoft Office security documentation
  • Mark-of-the-Web (MOTW) enforcement strengthened in Office 2016. Zone identifier (Zone.Identifier ADS) used as security input to trigger Protected View. OLE manipulation techniques discovered to bypass MOTW. Source: Microsoft Office security model
  • CISA issues Binding Operational Directive 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities. Establishes KEV catalog and mandatory remediation timelines for all Federal Civilian Executive Branch (FCEB) agencies. 44 U.S.C. § 3553(b)(2). Source: https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities
  • Microsoft begins blocking macros by default in Office documents from the internet (MOTW-tagged). Significant security improvement but OLE object embedding and security feature bypass techniques remain viable attack vectors. Source: Microsoft Security Blog
  • Multiple CVEs in 2024 demonstrate ongoing OLE security feature bypass capability. Protected View, MOTW, and macro blocking repeatedly circumvented via OLE property manipulation, zone identifier spoofing, and embedded object techniques. 6th generation of OLE bypass attacks. Source: MSRC Security Update Guides 2024
  • Microsoft January 2026 Patch Tuesday releases security update for CVE-2026-21509. Classified as Security Feature Bypass, CVSS 7.8 HIGH. Fixes reliance on untrusted inputs in security decision within Office OLE subsystem. Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
  • Discovered
  • First Exploitation
  • NVD publishes CVE-2026-21509 with CVSS v3.1 base score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Attack vector local, complexity low, no privileges required, user interaction required. Full CIA impact. Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21509
  • CISA adds CVE-2026-21509 to Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation in the wild. KEV addition date: January 26, 2026. Remediation deadline: February 16, 2026 (21 days). CISA notes some impacted products are EoL/EoS — advises discontinuation. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509
  • Disclosed
  • Vicarius vSociety publishes detection and mitigation scripts for CVE-2026-21509, demonstrating community urgency around the vulnerability. Third-party tooling available for identification and remediation verification. Source: https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability
  • CISA adds 4 additional Microsoft vulnerabilities to KEV catalog on the same day — CVE-2026-21514 (Office Word untrusted input), CVE-2026-21519 (Windows DWM type confusion), CVE-2026-21533 (RDP privilege management), CVE-2026-21510 (Windows Shell protection failure). Demonstrates sustained campaign against Microsoft products. Due date March 3, 2026. Source: CISA KEV Catalog
  • NVD record for CVE-2026-21509 updated with additional references and metadata. CISA-ADP adds government resource tag. Concurrent with February 2026 Patch Tuesday which adds 4 more Office/Windows KEVs (CVE-2026-21514, CVE-2026-21519, CVE-2026-21533, CVE-2026-21510). Source: NVD
  • FIRST EPSS score for CVE-2026-21509 at 0.13006 (13% exploitation probability in next 30 days) — significantly elevated above baseline. Confirms active exploitation aligns with CISA KEV classification. Tenable classifies as 'Vulnerability of Interest.' Source: https://www.first.org/epss/
  • MANDATORY REMEDIATION DEADLINE for CVE-2026-21509 under BOD 22-01. All FCEB agencies must have applied the January 2026 security update OR removed affected systems from their network by this date. Non-compliance reportable to CISA. No waivers or exceptions available. Source: CISA BOD 22-01
  • As of 2026-05-29, CVE-2026-21509 (Office OLE/MOTW bypass) is patched but remains under active, multi-actor exploitation: Proofpoint reports attempts ongoing into mid-May 2026 and VulnCheck lists it as routinely targeted. Now attributed (record says "Unattributed") to APT28/TA422 (Operation Neusploit), DPRK TA406, and Razor Tiger; still in CISA KEV, ransomware use Unknown.

Sources cited for CVE-2026-21509

Threats related to CVE-2026-21509

Detection coverage for TL-2026-0021

As of 2026-02-02, Threadlinqs Intelligence publishes 16 detection rule(s) for TL-2026-0021 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats