cbcvebase.
CVE-2026-21509
published 2026-01-26

CVE-2026-21509: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

PriorityP183high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-02-16
Exploited in the wild
EPSS
72.15%
99.4th percentile
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_2016>= 16.0.0 < 16.0.5539.100116.0.5539.1001
microsoftmicrosoft_office_2019>= 19.0.0 < 16.0.10417.2009516.0.10417.20095
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2024>= 16.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftoffice
microsoftoffice
microsoftoffice_long_term_servicing_channel
microsoftoffice_long_term_servicing_channel
msrcmicrosoft_365_apps_for_enterprise_for_32-bit_systems
msrcmicrosoft_365_apps_for_enterprise_for_64-bit_systems
msrcmicrosoft_office_2016
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions
msrcmicrosoft_office_ltsc_2021_for_32-bit_editions
msrcmicrosoft_office_ltsc_2021_for_64-bit_editions
msrcmicrosoft_office_ltsc_2024_for_32-bit_editions
msrcmicrosoft_office_ltsc_2024_for_64-bit_editions

Detection & IOCsextracted from sources · hover to see the quote

otherEAB22AC3-30C1-11CF-A7EB-0000C05BAE0B
domainwellnesscaremed[.]com
hashaefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1fa
registryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}
  • CVE-2026-21509 exploits the Shell.Explorer.1 COM object (CLSID EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B) embedded in a specially crafted RTF document; hunt for OLE objects referencing this CLSID in RTF files.
  • Exploitation forces an outbound connection to an attacker-controlled WebDAV server to retrieve and execute a remote .lnk file; monitor for Office processes initiating WebDAV (HTTP/HTTPS) connections followed by .lnk execution.
  • Spear-phishing lure subjects used in this campaign: 'Hydro-meteorological Warnings', 'Invitation to Military Training Programme', and 'Weapon Smuggling Alerts' — flag emails with these subjects carrying Office/RTF attachments.
  • Mitigation registry key: set CompatibilityFlags DWORD = 0x400 under HKLM\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}; absence of this key on unpatched systems indicates exposure.
  • ·The linkage between CVE-2026-21509 and CVE-2026-21513 (i.e., that the retrieved .lnk files exploit CVE-2026-21513) is inferred from shared C&C infrastructure (wellnesscaremed[.]com) and has NOT been independently confirmed by TrendAI Research.
  • ·The SHA256 hash aefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1fa is attributed to CVE-2026-21513 (MSHTML), not directly to CVE-2026-21509; it is relevant only if the two-stage chain is confirmed.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.