CVE-2026-21509
published 2026-01-26CVE-2026-21509: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
PriorityP183high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-02-16
Exploited in the wild
EPSS
72.15%
99.4th percentile
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2016 | >= 16.0.0 < 16.0.5539.1001 | 16.0.5539.1001 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < 16.0.10417.20095 | 16.0.10417.20095 |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_64-bit_editions | — | — |
Detection & IOCsextracted from sources · hover to see the quote
registryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}↗
- →CVE-2026-21509 exploits the Shell.Explorer.1 COM object (CLSID EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B) embedded in a specially crafted RTF document; hunt for OLE objects referencing this CLSID in RTF files. ↗
- →Exploitation forces an outbound connection to an attacker-controlled WebDAV server to retrieve and execute a remote .lnk file; monitor for Office processes initiating WebDAV (HTTP/HTTPS) connections followed by .lnk execution. ↗
- →Spear-phishing lure subjects used in this campaign: 'Hydro-meteorological Warnings', 'Invitation to Military Training Programme', and 'Weapon Smuggling Alerts' — flag emails with these subjects carrying Office/RTF attachments. ↗
- →Mitigation registry key: set CompatibilityFlags DWORD = 0x400 under HKLM\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}; absence of this key on unpatched systems indicates exposure. ↗
- ·The linkage between CVE-2026-21509 and CVE-2026-21513 (i.e., that the retrieved .lnk files exploit CVE-2026-21513) is inferred from shared C&C infrastructure (wellnesscaremed[.]com) and has NOT been independently confirmed by TrendAI Research. ↗
- ·The SHA256 hash aefd15e3c395edd16ede7685c6e97ca0350a702ee7c8585274b457166e86b1fa is attributed to CVE-2026-21513 (MSHTML), not directly to CVE-2026-21509; it is relevant only if the two-stage chain is confirmed. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Office Security Feature Bypass Vulnerability
cisa·2026-01-26·CVSS 7.8
CVE-2026-21509 [HIGH] CWE-807 Microsoft Office Security Feature Bypass Vulnerability
Vulnerability: Microsoft Office Security Feature Bypass Vulnerability
Affected: Microsoft Office
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: Please adhere to Microsoft’s recommended guidelines to address this vulnerability. Implement all final mitigations provid
Microsoft
Microsoft Office Security Feature Bypass Vulnerability
vendor_msrc·2026-01-13·CVSS 7.8
CVE-2026-21509 [HIGH] CWE-807 Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
Description: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
FAQ: Are the updates for Microsoft Office 2016 and 2019 currently available?
Yes. As of January 26, 2026, the security update for Microsoft Office 2016 and 2019 is available. Customers running Microsoft Office 2016 and 2019 should ensure the update is installed to be protected from this vulnerability.
FAQ: How do I know what version of Office 2016 and 2019 I am running?
On January 26
GHSA
GHSA-ch84-h92g-mw93: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally
ghsa_unreviewed·2026-01-26
CVE-2026-21509 [HIGH] CWE-807 GHSA-ch84-h92g-mw93: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
VulnCheck
Microsoft Office Security Feature Bypass Vulnerability
vulncheck·2026·CVSS 7.8
CVE-2026-21509 [HIGH] CWE-807 Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Affected: Microsoft Office
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jan; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuP
VulnCheck
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
vulncheck·2017·CVSS 8.8
CVE-2017-6742 [HIGH] CWE-119 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Affected: Cisco IOS and IOS XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170629-snmp.html; https://cisa.gov/news-events/cybersecurity-advisories/aa23-108; https://www.ncsc.gov.uk/news/apt28-exploits-known-vulnerability-to-carry-out-reconnaissance-and-deploy-malware-on-cisco-routers; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://
No detection rules found.
No public exploits indexed.
Recorded Future
June 2026 CVE Landscape
blogs_recorded_future·2026-07-10·CVSS 9.1
CVE-2026-35616 [CRITICAL] June 2026 CVE Landscape
## June 2026 CVE Landscape
In June 2026, Insikt Group® identified 60 high-impact vulnerabilities that should be prioritized for remediation , 30 of which had a Very Critical Recorded Future Risk Score. This represents a 49% increase from last month. 23 of the 60 vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 34 were reported by vendors, and three were primarily surfaced through honeypot data.
The 60 vulnerabilities in this report affected products from 36 vendors, with Microsoft accounting for approximately 18% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform
Hackernews
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
blogs_hackernews·2026-06-02·CVSS 8.4
CVE-2025-8088 [HIGH] Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation.
Per Sekoia, the activity involves the weaponization of CVE-2025-8088 , a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used to retrieve an intermediate Visual Basic Script (VBScript) downloaders codenamed GammaLoad. The infection chain was observed by the French cybersecurity company in January 2026.
Securelist
Exploits and vulnerabilities in Q1 2026
blogs_securelist·2026-05-07·CVSS 7.8
CVE-2026-21519 [HIGH] Exploits and vulnerabilities in Q1 2026
Alexander Kolesnikov
Table of Contents
Statistics on registered vulnerabilities
Exploitation statistics
Windows and Linux vulnerability exploitation
Most common published exploits
Vulnerability exploitation in APT attacks
C2 frameworks
Notable vulnerabilities
CVE-2026-21519: Desktop Window Manager vulnerability
RegPwn (CVE-2026-21533): a system settings access control vulnerability
CVE-2026-21514: a Microsoft Office vulnerability
Clawdbot (CVE-2026-25253): an OpenClaw vulnerability
CVE-2026-34070: LangChain framework vulnerability
CVE-2026-22812: an OpenCode vulnerability
Conclusion and advice
Authors
Alexander Kolesnikov
During Q1 2026, the exploit kits leveraged by threat actors to target user systems expanded once again, incorporating new exploits for the Microsoft Off
Hackernews
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
blogs_hackernews·2026-04-08·CVSS 7.8
[HIGH] APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
The Russian threat actor known as APT28 (aka Forest Blizzard and Pawn Storm) has been linked to a fresh spear-phishing campaign targeting Ukraine and its allies to deploy a previously undocumented malware suite codenamed PRISMEX .
"PRISMEX combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command-and-control," Trend Micro researchers Feike Hacquebord and Hiroyuki Kakara said in a technical report. The campaign is believed to be active since at least September 2025.
The activity has target
Trendmicro
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
blogs_trendmicro·2026-03-26·CVSS 7.8
[HIGH] Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
APT y ataques dirigidos
## Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed.
By: Feike Hacquebord, Hiroyuki Kakara Mar 26, 2026 Read time: ( words)
Save to Folio
Key takeaways:
Prolific Russia-aligned Advanced Persistent Threat (APT) group Pawn Storm has been using PRISMEX, a collection of interconnected malware components to target the defense supply chain of Ukraine and its allies including Czech Republic, Poland, Romania, Slovakia, Slovenia, and Turkey.
PRISMEX combines advanced steganography, component object model (COM) hijacking, an
Trendmicro
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
blogs_trendmicro·2026-03-26·CVSS 7.8
[HIGH] Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
APT & Targeted Attacks
## Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defence supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analysed.
By: Feike Hacquebord, Hiroyuki Kakara Mar 26, 2026 Read time: ( words)
Save to Folio
Key takeaways:
Prolific Russia-aligned Advanced Persistent Threat (APT) group Pawn Storm has been using PRISMEX, a collection of interconnected malware components to target the defence supply chain of Ukraine and its allies including Czech Republic, Poland, Romania, Slovakia, Slovenia, and Turkey.
PRISMEX combines advanced steganography, component object model (COM) hijacking, and
Trendmicro
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
blogs_trendmicro·2026-03-26·CVSS 7.8
[HIGH] Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
APT und gezielte Angriffe
## Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed.
By: Feike Hacquebord, Hiroyuki Kakara Mar 26, 2026 Read time: ( words)
Save to Folio
Key takeaways:
Prolific Russia-aligned Advanced Persistent Threat (APT) group Pawn Storm has been using PRISMEX, a collection of interconnected malware components to target the defense supply chain of Ukraine and its allies including Czech Republic, Poland, Romania, Slovakia, Slovenia, and Turkey.
PRISMEX combines advanced steganography, component object model (COM) hijacking,
Trendmicro
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
blogs_trendmicro·2026-03-26·CVSS 7.8
[HIGH] Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
APT & Targeted Attacks
## Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed.
By: Feike Hacquebord, Hiroyuki Kakara Mar 26, 2026 Read time: ( words)
Save to Folio
Key takeaways:
Prolific Russia-aligned Advanced Persistent Threat (APT) group Pawn Storm has been using PRISMEX, a collection of interconnected malware components to target the defense supply chain of Ukraine and its allies including Czech Republic, Poland, Romania, Slovakia, Slovenia, and Turkey.
PRISMEX combines advanced steganography, component object model (COM) hijacking, and
Trendmicro
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
blogs_trendmicro·2026-03-26·CVSS 7.8
[HIGH] Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
APT & Targeted Attacks
## Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed.
By: Feike Hacquebord, Kakara Hiroyuki 2026/03/26 Read time: ( words)
Save to Folio
Key takeaways:
Prolific Russia-aligned Advanced Persistent Threat (APT) group Pawn Storm has been using PRISMEX, a collection of interconnected malware components to target the defense supply chain of Ukraine and its allies including Czech Republic, Poland, Romania, Slovakia, Slovenia, and Turkey.
PRISMEX combines advanced steganography, component object model (COM) hijacking, and l
abuse.ch
BEARDSHELL - malicious payload (SHA-256 file hash)
abuse_ch·2026-03-15
CVE-2026-21509 BEARDSHELL - malicious payload (SHA-256 file hash)
ThreatFox IOC: BEARDSHELL malicious payload
Indicator Type: SHA-256 file hash
Tags: APT28
Reference: https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2026/02/kpmg-ctip-apt-28-17-feb-2026.pdf
Confidence: 85%
Eset
Sednit reloaded: Back in the trenches
blogs_eset·2026-03-10
Sednit reloaded: Back in the trenches
Award-winning news, views, and insight from the ESET security community
ESET Research
## Sednit reloaded: Back in the trenches
The resurgence of one of Russia’s most notorious APT groups
ESET Research
10 Mar 2026 • , 13 min. read
Since April 2024, Sednit’s advanced development team has reemerged with a modern toolkit centered on two paired implants, BeardShell and Covenant, each using a different cloud provider for resilience. This dual‑implant approach enabled long‑term surveillance of Ukrainian military personnel. Interestingly, these current toolsets show a direct code lineage to the group’s 2010‑era implants.
ESET researchers traced the reactivation of Sednit’s advanced implant team to a 2024 case in Ukraine, where a keylogger named SlimAgent was deployed.
SlimAgent code was
Bleepingcomputer
APT28 hackers deploy customized variant of Covenant open-source tool
blogs_bleepingcomputer·2026-03-10·CVSS 7.8
[HIGH] APT28 hackers deploy customized variant of Covenant open-source tool
## APT28 hackers deploy customized variant of Covenant open-source tool
## Bill Toulas
The Russian state-sponsored APT28 threat group is using a custom variant of the open-source Covenant post-exploitation framework for long-term espionage operations.
Also tracked as Fancy Bear, Forest Blizzard, Strontium, and Sednit, the APT28 hacker group is known for developing high-end implants and breaching notable entities, such as the German Parliament , multiple French organizations , government networks in Poland , and European NATO member countries .
Researchers at cybersecurity company ESET noticed that since April 2024, the Russian group has started using in attacks two implants named BeardShell and Covenant.
"This dual-implant approach enabled long-term surveillance of Ukrainian military
Recorded Future
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
blogs_recorded_future·2026-02-24·CVSS 7.8
[HIGH] January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
## January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.
What security teams need to know:
APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
Microsoft and SmarterTools lead concerns: These vendors accounted
Krebs
Patch Tuesday, February 2026 Edition
blogs_krebs·2026-02-10·CVSS 7.8
CVE-2026-21510 [HIGH] Patch Tuesday, February 2026 Edition
Microsoft today released updates to fix more than 50 security holes in its Windows operating systems and other software, including patches for a whopping six “zero-day” vulnerabilities that attackers are already exploiting in the wild.
Zero-day #1 this month is CVE-2026-21510, a security feature bypass vulnerability in Windows Shell wherein a single click on a malicious link can quietly bypass Windows protections and run attacker-controlled content without warning or consent dialogs. CVE-2026-21510 affects all currently supported versions of Windows.
The zero-day flaw CVE-2026-21513 is a security bypass bug targeting MSHTML, the proprietary engine of the default Web browser in Windows. CVE-2026-21514 is a related security feature bypass in Microsoft Word.
The zero-day CVE-2026-21533 all
Krebs
Patch Tuesday, February 2026 Edition
blogs_krebs·2026-02-10·CVSS 7.8
CVE-2026-21510 [HIGH] Patch Tuesday, February 2026 Edition
Microsoft today released updates to fix more than 50 security holes in its Windows operating systems and other software, including patches for a whopping six “zero-day” vulnerabilities that attackers are already exploiting in the wild.
Zero-day #1 this month is CVE-2026-21510 , a security feature bypass vulnerability in Windows Shell wherein a single click on a malicious link can quietly bypass Windows protections and run attacker-controlled content without warning or consent dialogs. CVE-2026-21510 affects all currently supported versions of Windows.
The zero-day flaw CVE-2026-21513 is a security bypass bug targeting MSHTML , the proprietary engine of the default Web browser in Windows. CVE-2026-21514 is a related security feature bypass in Microsoft Word.
The zero-day CVE-2026-21533 a
Zscaler
Operation Neusploit: APT28 Uses CVE-2026-21509 | ThreatLabz
blogs_zscaler·2026-02-02·CVSS 7.8
[HIGH] Operation Neusploit: APT28 Uses CVE-2026-21509 | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bleepingcomputer
Russian hackers exploit recently patched Microsoft Office bug in attacks
blogs_bleepingcomputer·2026-02-02·CVSS 7.8
CVE-2026-21509 [HIGH] Russian hackers exploit recently patched Microsoft Office bug in attacks
## Russian hackers exploit recently patched Microsoft Office bug in attacks
## Bill Toulas
Ukraine’s Computer Emergency Response Team (CERT) says that Russian hackers are exploiting CVE-2026-21509, a recently patched vulnerability in multiple versions of Microsoft Office.
On January 26, Microsoft released an emergency out-of-band security update marking CVE-2026-21509 as an actively exploited zero-day flaw.
CERT-UA detected the distribution of malicious DOC files exploiting the flaw, themed around EU COREPER consultations in Ukraine, just three days after Microsoft's alert.
In other cases, the emails impersonated the Ukrainian Hydrometeorological Center and were sent to over 60 government-related addresses.
However, the agency says that the metadata associated with the document shows
Talos
Microsoft releases update to address zero-day vulnerability in Microsoft Office
blogs_talos·2026-01-29·CVSS 7.8
CVE-2026-21509 [HIGH] Microsoft releases update to address zero-day vulnerability in Microsoft Office
- Microsoft has published three out-of-band (OOB) updates so far in January 2026. One of these updates was released to address a vulnerability, CVE-2026-21509, affecting Microsoft Office that has been reportedly exploited in the wild.
- Additional OOB updates have been published to resolve operational issues experienced following installation of the updates released as part of the standard Microsoft Patch Tuesday process.
CVE-2026-21509 was published to address a security feature bypass vulnerability affecting Microsoft Office. This vulnerability was rated as “Important” and received a CVSS 3.1 score of 7.8. This vulnerability is considered “local,” meaning that it must be triggered by an attacker with access to an affected system, or by convincing a victim to open a malicious Office docu
Talos
Microsoft releases update to address zero-day vulnerability in Microsoft Office
blogs_talos·2026-01-29·CVSS 7.8
CVE-2026-21509 [HIGH] Microsoft releases update to address zero-day vulnerability in Microsoft Office
## Microsoft releases update to address zero-day vulnerability in Microsoft Office
Microsoft has published three out-of-band (OOB) updates so far in January 2026. One of these updates was released to address a vulnerability, CVE-2026-21509 , affecting Microsoft Office that has been reportedly exploited in the wild.
Additional OOB updates have been published to resolve operational issues experienced following installation of the updates released as part of the standard Microsoft Patch Tuesday process.
CVE-2026-21509 was published to address a security feature bypass vulnerability affecting Microsoft Office. This vulnerability was rated as “Important” and received a CVSS 3.1 score of 7.8. This vulnerability is considered “local,” meaning that it must be triggered by an attacker with acces
Bleepingcomputer
Microsoft patches actively exploited Office zero-day vulnerability
blogs_bleepingcomputer·2026-01-26
Microsoft patches actively exploited Office zero-day vulnerability
## Microsoft patches actively exploited Office zero-day vulnerability
## Sergiu Gatlan
"Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. An attacker must send a user a malicious Office file and convince them to open it," Microsoft explained.
"This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office which protect users from vulnerable COM/OLE controls."
"Customers on Office 2021 and later will be automatically protected via a service-side change, but will be required to restart their Office applications for this to take effect," it added.
Microsoft has also provided confusing mitigation measures that could "reduce the severity of exploitation."
Wiz
CVE-2026-21509 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21509 [HIGH] CVE-2026-21509 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21509 :
vulnerability analysis and mitigation
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Source : NVD
## 7.8
Score
Published January 26, 2026
Severity HIGH
CNA Score 7.8
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 91.8
Exploitation Probability (EPSS) 7.5
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
Free Vulnerability Assessment
## Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk lev
Eset
Sednit reloaded: Back in the trenches
blogs_eset
Sednit reloaded: Back in the trenches
Since April 2024, Sednit’s advanced development team has reemerged with a modern toolkit centered on two paired implants, BeardShell and Covenant, each using a different cloud provider for resilience. This dual‑implant approach enabled long‑term surveillance of Ukrainian military personnel. Interestingly, these current toolsets show a direct code lineage to the group’s 2010‑era implants.
> Key points of this blogpost:
>
> - ESET researchers traced the reactivation of Sednit’s advanced implant team to a 2024 case in Ukraine, where a keylogger named SlimAgent was deployed.
> - SlimAgent code was derived from Xagent, Sednit’s flagship backdoor from the 2010s.
> - During that operation, BeardShell, a second Sednit‑developed implant, was deployed. It executes PowerShell commands via a legitima
Zscaler
Home Page | CXO Revolutionaries
blogs_zscaler·CVSS 7.8
[HIGH] Home Page | CXO Revolutionaries
Editor’s Pick
Digital Transformation
## Zscaler, NACD partner to advance boards’ cyber understanding
I’m thrilled to announce that Zscaler is now an official partner of the National Association of Corporate Directors (NACD), the premier membership group of U.S.-based board members across organizations of all sizes.
Kavitha Mariappan
## latest Insights
CXO Monthly Roundup, February 2026: Middle East conflict–themed threat activity, Iran-nexus APT Dust Specter, APT28 Operation Neusploit (CVE-2026-21509), APT37 Ruby Jumper air-gap capabilities, analysis of GuLoader and Marco Stealer, and more
Deepen Desai
The Director’s Cut: Cloud Disruption as Iran Retaliates
Rob Sloan
Cyber Governance
The Director’s Cut: U.K. Cyber Tests Expose Banks’ Weakness on Security Basics
Rob Sloan
CXO M
Zscaler
Insights Landing | CXO Revolutionaries
blogs_zscaler·CVSS 7.8
[HIGH] Insights Landing | CXO Revolutionaries
insights
## An Executive- Level Resource
Actionable, practical advice for leading secure digital transformation initiatives from experienced CXOs.
Tools and Resources
Cyber Governance
Learn More
Cyber Governance
Threats and Risks
Customer Journeys
Cyber Governance
Threats and Risks
Customer Journeys
Cyber Governance
Threats and Risks
Customer Journeys
Cyber Governance
Learn More
Editor’s Pick
Digital Transformation
## Zscaler, NACD partner to advance boards’ cyber understanding
I’m thrilled to announce that Zscaler is now an official partner of the National Association of Corporate Directors (NACD), the premier membership group of U.S.-based board members across organizations of all sizes.
Kavitha Mariappan
## latest Insights
CXO Monthly Roundup, February 2026: Middl
Recorded Future
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
blogs_recorded_future·CVSS 4.9
[MEDIUM] January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
# January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.
What security teams need to know:
- APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
- Microsoft and SmarterTools lead concerns: These vendors accounte
Zscaler
CXO Monthly Roundup, February 2026: Middle East conflict–themed threat activity, Iran-nexus APT Dust Specter, APT28 Operation Neusploit (CVE-2026-21509), APT37 Ruby Jumper air-gap capabilities, analys
blogs_zscaler·CVSS 7.8
CVE-2026-21509 [HIGH] CXO Monthly Roundup, February 2026: Middle East conflict–themed threat activity, Iran-nexus APT Dust Specter, APT28 Operation Neusploit (CVE-2026-21509), APT37 Ruby Jumper air-gap capabilities, analys
## CXO Monthly Roundup, February 2026: Middle East conflict–themed threat activity, Iran-nexus APT Dust Specter, APT28 Operation Neusploit (CVE-2026-21509), APT37 Ruby Jumper air-gap capabilities, analysis of GuLoader and Marco Stealer, and more
Deepen Desai
Contributor
Zscaler
## Mar 9, 2026
Highlights from the Zscaler ThreatLabz team's February 2026 research.
The CXO Monthly Roundup provides the latest Zscaler ThreatLabz research, alongside insights into other cyber-related subjects that matter to technology executives. This monthly roundup highlights findings from a surge in cybercriminal activity capitalizing on the elevated political climate in the Middle East, Dust Specter (Iran-nexus) activity targeting government officials in Iraq, APT28’s Operation Neusploit leveraging CVE-2
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerabilityhttps://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerabilityhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509
2026-01-26
Published
2026-01-26
Added to CISA KEV
Exploited in the wild