APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via COREPER-Themed Spear-Phishing
APT28 Microsoft Office Security Feature Bypass (TL-2026-0133), also tracked as UAC-0001, is a high-severity advanced persistent threat campaign scored CVSS 7.8, first published 2026-02-23. It is attributed to APT28 (Russia) with high confidence, affects Microsoft 365 Apps for Enterprise, references 1 CVE (CVE-2026-21509), maps to 31 MITRE ATT&CK techniques (T1003.001, T1005, T1016), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-0133
- Threat ID
- TL-2026-0133
- Also known as
- UAC-0001, CERT-UA #19542
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- APT
- First published
- 2026-02-23
- Last reviewed
- 2026-02-23
- Attribution
- APT28
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government, diplomacy, military, defense, critical-infrastructure, think-tanks, media
- Target regions
- Ukraine, European Union, NATO, Eastern Europe, Western Europe
- Detection rules
- 9
- Indicators of compromise
- 18
APT28 (Fancy Bear / UAC-0001 / Forest Blizzard) exploits CVE-2026-21509, a Microsoft Office security feature bypass (CVSS 7.8, CWE-807), in targeted spear-phishing campaigns against Ukraine and EU member states. Weaponized DOC files themed around EU COREPER consultations on Ukraine bypass Office security protections. CISA added CVE-2026-21509 to KEV on January 26, 2026 with a February 16 remediation deadline. Patched in January 2026 Patch Tuesday.
How APT28 Microsoft Office Security Feature Bypass works
CERT-UA (alert #19542) identified APT28 (tracked as UAC-0001 in Ukrainian taxonomy) actively exploiting CVE-2026-21509 against Ukrainian government entities and EU member state institutions in February 2026. The campaign uses weaponized Microsoft Word documents themed around EU Council COREPER (Committee of Permanent Representatives) consultations regarding Ukraine policy.
## CVE-2026-21509 Technical Details
CVE-2026-21509 is a Microsoft Office security feature bypass caused by reliance on untrusted inputs in a security decision (CWE-807). The vulnerability has: - CVSS 3.1 Base Score: 7.8 (HIGH) - Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - Attack Vector: Local (requires user to open malicious document) - Attack Complexity: Low - Privileges Required: None - User Interaction: Required (victim must open the weaponized DOC) - Impact: High confidentiality, integrity, and availability impact
The vulnerability allows an unauthorized attacker to bypass Microsoft Office security features locally. When a user opens a specially crafted document, Office fails to properly validate security-relevant inputs, allowing the attacker to bypass protections such as Protected View, macro security warnings, or Mark of the Web (MOTW) checks that would normally prevent malicious code execution.
## Affected Products
All major Microsoft Office versions are vulnerable: - Microsoft 365 Apps for Enterprise (x64 and x86) - Microsoft Office 2016 (x64 and x86) - Microsoft Office 2019 (x64 and x86) - Microsoft Office LTSC 2021 (x64 and x86) - Microsoft Office LTSC 2024 (x64 and x86)
## APT28 Campaign Details
APT28 (also known as Fancy Bear, Sofacy, Sednit, Forest Blizzard, Pawn Storm, and STRONTIUM) is Unit 26165 of Russia's GRU (Main Intelligence Directorate). The group has conducted cyber operations since at least 2004, targeting government, military, security organizations, and critical infrastructure worldwide.
### Campaign Characteristics: - **Lure theme**: EU COREPER consultations on Ukraine — highly targeted geopolitical content designed to appear legitimate to EU and Ukrainian government officials - **Delivery**: Spear-phishing emails with weaponized DOC attachments - **Exploit**: CVE-2026-21509 bypasses Office security features, enabling payload execution without standard security warnings - **Targets**: Ukrainian government entities, EU member state diplomatic missions, EU Council staff - **Attribution**: CERT-UA attributes to UAC-0001 (APT28) based on TTPs, infrastructure, and targeting patterns consistent with GRU operations
### Historical Context: APT28 has a documented pattern of exploiting Microsoft Office vulnerabilities in campaigns against Ukraine and European targets: - CVE-2023-23397 (Outlook privilege escalation) — used against Ukrainian and European organizations - CVE-2023-38831 (WinRAR) — weaponized against Ukraine military - CVE-2017-0199 (Office/WordPad RCE) — extensive use in APT28 campaigns - Repeated targeting of EU diplomatic communications, NATO, and OSCE
## CISA KEV Details
- Added to KEV: January 26, 2026 - Remediation deadline: February 16, 2026 (BOD 22-01) - Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use - Known ransomware use: Not confirmed
## Patch Information
Microsoft patched CVE-2026-21509 in the January 14, 2026 Patch Tuesday release. Organizations that have not applied the January 2026 cumulative update remain vulnerable. The CISA KEV deadline of February 16 has already passed — any unpatched systems are in violation of BOD 22-01 requirements.
MITRE ATT&CK techniques used in TL-2026-0133
credential-access
collection
T1005 Data from Local System; T1056.001 Keylogging; T1114.001 Local Email Collection; T1560.001 Archive via Utility
discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087.002 Domain Account
lateral-movement
T1021.002 SMB/Windows Admin Shares
defense-evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1221 Template Injection
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.005 Visual Basic; T1203 Exploitation for Client Execution; T1204.002 Malicious File
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1573.002 Asymmetric Cryptography
initial-access
T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment
persistence
T1547.001 Registry Run Keys / Startup Folder
defense-impairment
T1553.005 Mark-of-the-Web Bypass; T1685 Disable or Modify Tools
resource-development
T1587.004 Exploits; T1588.005 Exploits; T1608.001 Upload Malware
Affected products and versions in APT28 Microsoft Office Security Feature Bypass
- Microsoft — 365 Apps for Enterprise
Vulnerable versions: All versions prior to January 2026 update
Fixed in: January 2026 Patch Tuesday - Microsoft — Office 2016
Vulnerable versions: x64 and x86
Fixed in: January 2026 security update - Microsoft — Office 2019
Vulnerable versions: x64 and x86
Fixed in: January 2026 security update - Microsoft — Office LTSC 2021
Vulnerable versions: x64 and x86
Fixed in: January 2026 security update - Microsoft — Office LTSC 2024
Vulnerable versions: x64 and x86
Fixed in: January 2026 security update
Remediation for APT28 Microsoft Office Security Feature Bypass
Patches
- Microsoft January 2026 Patch Tuesday (KB5034567) — fixes CVE-2026-21509
- Update Microsoft 365 Apps, Office 2016, 2019, LTSC 2021, LTSC 2024
Immediate actions
- Apply January 2026 Patch Tuesday updates for Microsoft Office immediately
- Block DOC/DOCX attachments themed around EU COREPER or Ukraine consultations at email gateway
- Enable Protected View and block macros from internet-sourced documents
- Alert SOC to spear-phishing attempts targeting diplomatic and government staff
- Check for indicators of compromise on systems that opened suspicious Office documents
Workarounds
- Block Office file downloads from untrusted sources at proxy/firewall
- Configure Office to open internet-sourced documents in Protected View (default)
- Disable OLE/ActiveX content in Office documents via Group Policy
- Use Application Guard for Office to isolate untrusted documents
Longer-term hardening
- Implement Attack Surface Reduction (ASR) rules for Office applications
- Deploy Microsoft Defender for Office 365 with Safe Attachments and Safe Links
- Enable Mark of the Web (MOTW) enforcement across all Office installations
- Implement email authentication (DMARC, DKIM, SPF) to detect spoofed sender domains
- Conduct targeted phishing awareness training for diplomatic and government staff
CVEs associated with APT28 Microsoft Office Security Feature Bypass
Weaknesses (CWE) in APT28 Microsoft Office Security Feature Bypass
CWE-807
Timeline of APT28 Microsoft Office Security Feature Bypass
- Microsoft releases January 2026 Patch Tuesday fixing CVE-2026-21509 among other vulnerabilities. Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
- CISA adds CVE-2026-21509 to Known Exploited Vulnerabilities catalog with remediation deadline February 16, 2026. Active exploitation confirmed. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- NVD publishes CVE-2026-21509 with CVSS 7.8 (HIGH). Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21509
- CERT-UA publishes alert #19542 attributing CVE-2026-21509 exploitation to APT28 (UAC-0001). Campaign targets Ukraine and EU member states using COREPER-themed spear-phishing. Source: https://cert.gov.ua/article/6287250
- Vicarius publishes detection and mitigation scripts for CVE-2026-21509. Source: https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability
- NVD completes full analysis of CVE-2026-21509 including CPE configurations for all affected Office versions.
- CISA BOD 22-01 remediation deadline for CVE-2026-21509. Federal agencies required to have applied patches or mitigations by this date.
- Campaign remains active. Unpatched organizations — especially in Ukrainian and EU government sectors — continue to be at risk. CISA deadline has passed.
- As of 2026-05-29, CVE-2026-21509 stays patched (Jan 2026 fix, still in CISA KEV) but active exploitation persists: Proofpoint confirms DPRK TA406 chaining it in Mar-Apr 2026, and APT28 remains fully operational (Ukraine prosecutor and Hellenic defense breaches, Storm-2754 router campaign). PATCHED retained; threat still active against unpatched targets.
Sources cited for APT28 Microsoft Office Security Feature Bypass
- CERT-UA #19542: APT28 Exploits CVE-2026-21509 Against Ukraine and EU
- NVD: CVE-2026-21509 Detail
- Microsoft Security Update Guide: CVE-2026-21509
- CISA KEV: CVE-2026-21509
- Vicarius: CVE-2026-21509 Detection Script
- Vicarius: CVE-2026-21509 Mitigation Script
- MITRE ATT&CK: APT28 Group Profile
- Microsoft: Forest Blizzard (APT28) Threat Intelligence
- CISA: Russian State-Sponsored Cyber Actors Target Cleared Defense Contractor Networks
- BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities
Threats related to APT28 Microsoft Office Security Feature Bypass
- Pawn Storm (APT28) Deploys PRISMEX Malware Suite via CVE-2026-21509 and CVE-2026-21513 Zero-Days Targeting Ukrainian Defense Supply Chain
- APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage Campaign (CVE-2026-21509)
- APT28 Operation Neusploit: MS Office CVE-2026-21509 Espionage Campaign
- CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV)
- APT28 PixyNetLoader — Loader Evolution 2024–2026 (Operation Neusploit, CVE-2026-21509)
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise
Detection coverage for TL-2026-0133
As of 2026-02-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0133 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.