CRITICALExploited in the wildUnknown

Microsoft Office Security Feature Bypass Vulnerability

Please adhere to Microsoft’s recommended guidelines to address this vulnerability. Implement all final mitigations provided by the vendor for Office 2021, and apply the interim corresponding mitigations for Office 2016 and Office 2019 until the final patch becomes available. For more information please see: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21509

CVE-2026-21509Published 6 months agoSource: CISA KEV

Affected packages

No package-level mapping for this advisory.

Exploit signal

Known exploited (CISA KEV)
Yes
EPSS score
72.15%
EPSS percentile
99.4%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 99%.

Sources

No external sources available.

Recommended response stack

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

Get incidents like this as alerts for your stack.

Join the beta
Microsoft Office Security Feature Bypass Vulnerability | HackTribune