Worrying security flaw in Microsoft Office has been fixed: update now or risk hackers accessing your files


  • Microsoft releases emergency patch for Office Zero-Day CVE-2026-21509
  • Vulnerability allows attackers to bypass OLE mitigations and execute malware
  • CISA adds vulnerability to KEV catalog; operating details remain confidential

Microsoft has released an emergency patch to address a high-severity Office vulnerability that is being exploited in the wild as a zero-day.

The bug is described as a security bypass flaw: “Using untrusted input in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally,” explains the National Vulnerability Database (NVD).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top