Worrying Microsoft Office security flaw fixed – update now or risk hackers accessing your files


  • Microsoft issues emergency patch for Office zero-day CVE-2026-21509
  • Vulnerability allows attackers to bypass OLE mitigations and execute malware
  • CISA adds errors to the KEV catalog; details of exploitation remain undisclosed

Microsoft has issued an emergency patch to fix a serious Office vulnerability that is being exploited in the wild as a zero-day.

The flaw is described as a security bypass flaw: “Depending on untrusted input in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally,” the National Vulnerability Database (NVD) explains.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top