APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via COREPER-Themed Spear-Phishing

APT28 Microsoft Office Security Feature Bypass (TL-2026-0133), also tracked as UAC-0001, is a high-severity advanced persistent threat campaign scored CVSS 7.8, first published 2026-02-23. It is attributed to APT28 (Russia) with high confidence, affects Microsoft 365 Apps for Enterprise, references 1 CVE (CVE-2026-21509), maps to 31 MITRE ATT&CK techniques (T1003.001, T1005, T1016), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-0133

Threat ID
TL-2026-0133
Also known as
UAC-0001, CERT-UA #19542
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
APT
First published
2026-02-23
Last reviewed
2026-02-23
Attribution
APT28
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government, diplomacy, military, defense, critical-infrastructure, think-tanks, media
Target regions
Ukraine, European Union, NATO, Eastern Europe, Western Europe
Detection rules
9
Indicators of compromise
18

APT28 (Fancy Bear / UAC-0001 / Forest Blizzard) exploits CVE-2026-21509, a Microsoft Office security feature bypass (CVSS 7.8, CWE-807), in targeted spear-phishing campaigns against Ukraine and EU member states. Weaponized DOC files themed around EU COREPER consultations on Ukraine bypass Office security protections. CISA added CVE-2026-21509 to KEV on January 26, 2026 with a February 16 remediation deadline. Patched in January 2026 Patch Tuesday.

How APT28 Microsoft Office Security Feature Bypass works

CERT-UA (alert #19542) identified APT28 (tracked as UAC-0001 in Ukrainian taxonomy) actively exploiting CVE-2026-21509 against Ukrainian government entities and EU member state institutions in February 2026. The campaign uses weaponized Microsoft Word documents themed around EU Council COREPER (Committee of Permanent Representatives) consultations regarding Ukraine policy.

## CVE-2026-21509 Technical Details

CVE-2026-21509 is a Microsoft Office security feature bypass caused by reliance on untrusted inputs in a security decision (CWE-807). The vulnerability has: - CVSS 3.1 Base Score: 7.8 (HIGH) - Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - Attack Vector: Local (requires user to open malicious document) - Attack Complexity: Low - Privileges Required: None - User Interaction: Required (victim must open the weaponized DOC) - Impact: High confidentiality, integrity, and availability impact

The vulnerability allows an unauthorized attacker to bypass Microsoft Office security features locally. When a user opens a specially crafted document, Office fails to properly validate security-relevant inputs, allowing the attacker to bypass protections such as Protected View, macro security warnings, or Mark of the Web (MOTW) checks that would normally prevent malicious code execution.

## Affected Products

All major Microsoft Office versions are vulnerable: - Microsoft 365 Apps for Enterprise (x64 and x86) - Microsoft Office 2016 (x64 and x86) - Microsoft Office 2019 (x64 and x86) - Microsoft Office LTSC 2021 (x64 and x86) - Microsoft Office LTSC 2024 (x64 and x86)

## APT28 Campaign Details

APT28 (also known as Fancy Bear, Sofacy, Sednit, Forest Blizzard, Pawn Storm, and STRONTIUM) is Unit 26165 of Russia's GRU (Main Intelligence Directorate). The group has conducted cyber operations since at least 2004, targeting government, military, security organizations, and critical infrastructure worldwide.

### Campaign Characteristics: - **Lure theme**: EU COREPER consultations on Ukraine — highly targeted geopolitical content designed to appear legitimate to EU and Ukrainian government officials - **Delivery**: Spear-phishing emails with weaponized DOC attachments - **Exploit**: CVE-2026-21509 bypasses Office security features, enabling payload execution without standard security warnings - **Targets**: Ukrainian government entities, EU member state diplomatic missions, EU Council staff - **Attribution**: CERT-UA attributes to UAC-0001 (APT28) based on TTPs, infrastructure, and targeting patterns consistent with GRU operations

### Historical Context: APT28 has a documented pattern of exploiting Microsoft Office vulnerabilities in campaigns against Ukraine and European targets: - CVE-2023-23397 (Outlook privilege escalation) — used against Ukrainian and European organizations - CVE-2023-38831 (WinRAR) — weaponized against Ukraine military - CVE-2017-0199 (Office/WordPad RCE) — extensive use in APT28 campaigns - Repeated targeting of EU diplomatic communications, NATO, and OSCE

## CISA KEV Details

- Added to KEV: January 26, 2026 - Remediation deadline: February 16, 2026 (BOD 22-01) - Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use - Known ransomware use: Not confirmed

## Patch Information

Microsoft patched CVE-2026-21509 in the January 14, 2026 Patch Tuesday release. Organizations that have not applied the January 2026 cumulative update remain vulnerable. The CISA KEV deadline of February 16 has already passed — any unpatched systems are in violation of BOD 22-01 requirements.

MITRE ATT&CK techniques used in TL-2026-0133

credential-access

T1003.001 LSASS Memory

collection

T1005 Data from Local System; T1056.001 Keylogging; T1114.001 Local Email Collection; T1560.001 Archive via Utility

discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087.002 Domain Account

lateral-movement

T1021.002 SMB/Windows Admin Shares

defense-evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1221 Template Injection

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.005 Visual Basic; T1203 Exploitation for Client Execution; T1204.002 Malicious File

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1573.002 Asymmetric Cryptography

initial-access

T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment

persistence

T1547.001 Registry Run Keys / Startup Folder

defense-impairment

T1553.005 Mark-of-the-Web Bypass; T1685 Disable or Modify Tools

resource-development

T1587.004 Exploits; T1588.005 Exploits; T1608.001 Upload Malware

Affected products and versions in APT28 Microsoft Office Security Feature Bypass

  • Microsoft — 365 Apps for Enterprise
    Vulnerable versions: All versions prior to January 2026 update
    Fixed in: January 2026 Patch Tuesday
  • Microsoft — Office 2016
    Vulnerable versions: x64 and x86
    Fixed in: January 2026 security update
  • Microsoft — Office 2019
    Vulnerable versions: x64 and x86
    Fixed in: January 2026 security update
  • Microsoft — Office LTSC 2021
    Vulnerable versions: x64 and x86
    Fixed in: January 2026 security update
  • Microsoft — Office LTSC 2024
    Vulnerable versions: x64 and x86
    Fixed in: January 2026 security update

Remediation for APT28 Microsoft Office Security Feature Bypass

Patches

  • Microsoft January 2026 Patch Tuesday (KB5034567) — fixes CVE-2026-21509
  • Update Microsoft 365 Apps, Office 2016, 2019, LTSC 2021, LTSC 2024

Immediate actions

  • Apply January 2026 Patch Tuesday updates for Microsoft Office immediately
  • Block DOC/DOCX attachments themed around EU COREPER or Ukraine consultations at email gateway
  • Enable Protected View and block macros from internet-sourced documents
  • Alert SOC to spear-phishing attempts targeting diplomatic and government staff
  • Check for indicators of compromise on systems that opened suspicious Office documents

Workarounds

  • Block Office file downloads from untrusted sources at proxy/firewall
  • Configure Office to open internet-sourced documents in Protected View (default)
  • Disable OLE/ActiveX content in Office documents via Group Policy
  • Use Application Guard for Office to isolate untrusted documents

Longer-term hardening

  • Implement Attack Surface Reduction (ASR) rules for Office applications
  • Deploy Microsoft Defender for Office 365 with Safe Attachments and Safe Links
  • Enable Mark of the Web (MOTW) enforcement across all Office installations
  • Implement email authentication (DMARC, DKIM, SPF) to detect spoofed sender domains
  • Conduct targeted phishing awareness training for diplomatic and government staff

CVEs associated with APT28 Microsoft Office Security Feature Bypass

CVE-2026-21509

Weaknesses (CWE) in APT28 Microsoft Office Security Feature Bypass

CWE-807

Timeline of APT28 Microsoft Office Security Feature Bypass

  • Microsoft releases January 2026 Patch Tuesday fixing CVE-2026-21509 among other vulnerabilities. Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
  • CISA adds CVE-2026-21509 to Known Exploited Vulnerabilities catalog with remediation deadline February 16, 2026. Active exploitation confirmed. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • NVD publishes CVE-2026-21509 with CVSS 7.8 (HIGH). Source: https://nvd.nist.gov/vuln/detail/CVE-2026-21509
  • CERT-UA publishes alert #19542 attributing CVE-2026-21509 exploitation to APT28 (UAC-0001). Campaign targets Ukraine and EU member states using COREPER-themed spear-phishing. Source: https://cert.gov.ua/article/6287250
  • Vicarius publishes detection and mitigation scripts for CVE-2026-21509. Source: https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability
  • NVD completes full analysis of CVE-2026-21509 including CPE configurations for all affected Office versions.
  • CISA BOD 22-01 remediation deadline for CVE-2026-21509. Federal agencies required to have applied patches or mitigations by this date.
  • Campaign remains active. Unpatched organizations — especially in Ukrainian and EU government sectors — continue to be at risk. CISA deadline has passed.
  • As of 2026-05-29, CVE-2026-21509 stays patched (Jan 2026 fix, still in CISA KEV) but active exploitation persists: Proofpoint confirms DPRK TA406 chaining it in Mar-Apr 2026, and APT28 remains fully operational (Ukraine prosecutor and Hellenic defense breaches, Storm-2754 router campaign). PATCHED retained; threat still active against unpatched targets.

Sources cited for APT28 Microsoft Office Security Feature Bypass

Threats related to APT28 Microsoft Office Security Feature Bypass

Detection coverage for TL-2026-0133

As of 2026-02-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0133 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats