APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via COREPER-Themed Spear-Phishing — Threadlinqs Intelligence
As of 2026-05-30, APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via COREPER-Themed Spear-Phishing is a high-severity apt threat attributed to APT28 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0133 · Severity: HIGH · CVSS: 7.8 · Status: PATCHED · Category: APT
Attribution: APT28 · Russia · ESPIONAGE
APT28 (Fancy Bear / UAC-0001 / Forest Blizzard) exploits CVE-2026-21509, a Microsoft Office security feature bypass (CVSS 7.8, CWE-807), in targeted spear-phishing campaigns against Ukraine and EU
CERT-UA (alert #19542) identified APT28 (tracked as UAC-0001 in Ukrainian taxonomy) actively exploiting CVE-2026-21509 against Ukrainian government entities and EU member state institutions in February 2026. The campaign uses weaponized Microsoft Word documents themed around EU Council COREPER (Committee of Permanent Representatives) consultations regarding Ukraine policy.
## CVE-2026-21509 Technical Details
CVE-2026-21509 is a Microsoft Office security feature bypass caused by reliance on untrusted inputs in a security decision (CWE-807). The vulnerability has:
- CVSS 3.1 Base Score: 7.8 (HIGH)
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Vector: Local (requires user to open malicious document)
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required (victim must open the weaponized DOC)
- Impact: High confidentiality, integrity, and availability impact
The vulnerability allows an unauthorized attacker to bypass Microsoft Office security features locally. When a user opens a specially crafted document, Office fails to properly validate security-relevant inputs, allowing the attacker to bypass protections such as Protected View, macro security warnings, or Mark of the Web (MOTW) checks that would normally prevent malicious code execution.
## Affected Products
All major Microsoft Office versions are vulnerable:
- Microsoft 365 Apps for Enterprise (x64 and x86)
- Microsoft Office 2016 (x64 and x86)
- Microsoft Office 2019 (x64 and x86)
- Microsoft Office LTSC 2021 (x64 and x86)
- Microsoft Office LTSC 2024 (x64 and x86)
## APT28 Campaign Details
APT28 (also known as Fancy Bear, Sofacy, Sednit, Forest Blizzard, Pawn Storm, and STRONTIUM) is Unit 26165 of Russia's GRU (Main Intelligence Directorate). The group has conducted cyber operations since at least 2004, targeting government, military, security organizations, and critical infrastructure worldwide.
### Campaign Characteristics:
- **Lure theme**: EU COREPER consultations on Ukraine — highly targeted geopolitical content designed to appear legitimate to EU and Ukrainian government officials
- **Delivery**: Spear-phishing emails with weaponized DOC attachments
- **Exploit**: CVE-2026-21509 bypasses Office security features, enabling payload execution without standard security warnings
- **Targets**: Ukrainian government entities, EU member state diplomatic missions, EU Council staff
- **Attribution**: CERT-UA attributes to UAC-0001 (APT28) based on TTPs, infrastructure, and targeting patterns consistent with GRU operations
### Historical Context:
APT28 has a documented pattern of exploiting Microsoft Office vulnerabilities in campaigns against Ukraine and European targets:
- CVE-2023-23397 (Outlook privilege escalation) — used against Ukrainian and European organizations
- CVE-2023-38831 (WinRAR) — weaponized against Ukraine military
- CVE-2017-0199 (Office/WordPad RCE) — extensive use in APT28 campaigns
- Repeated targeting of EU diplomatic communications, NATO, and OSCE
## CISA KEV Details
- Added to KEV: January 26, 2026
- Remediation deadline: February 16, 2026 (BOD 22-01)
- Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use
- Known ransomware use: Not confirmed
## Patch Information
Microsoft patched CVE-2026-21509 in the January 14, 2026 Patch Tuesday release. Organizations that have not applied the January 2026 cumulative update remain vulnerable. The CISA KEV deadline of February 16 has already passed — any unpatched systems are in violation of BOD 22-01 requirements.
Target sectors: government, diplomacy, military, defense, critical-infrastructure, think-tanks, media
Target regions: Ukraine, European Union, NATO, Eastern Europe, Western Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2026-21509, T1566.001, T1190, T1204.002, T1203, T1059.001, T1059.005, T1553.005, T1562.001, T1036.005, T1027