{
  "id": "CVE-2026-21509",
  "url": "https://spydr.io/cve/CVE-2026-21509",
  "published": "2026-01-26T18:16:38.540Z",
  "modified": "2026-06-25T05:16:53.167Z",
  "score": 7.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "score_source": "microsoft.com",
  "epss": 0.70795,
  "epss_percentile": 0.99385,
  "exploited": true,
  "kev": {
    "added": "2026-01-26",
    "due": "2026-02-16",
    "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "ransomware": "Unknown",
    "name": "Microsoft Office Security Feature Bypass Vulnerability",
    "notes": "Please adhere to Microsoft’s recommended guidelines to address this vulnerability. Implement all final mitigations provided by the vendor for Office 2021, and apply the interim corresponding mitigations for Office 2016 and Office 2019 until the final patch becomes available. For more information please see: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21509"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "Microsoft"
  ],
  "products": [
    "Microsoft 365 Apps for Enterprise",
    "Microsoft Office 2016",
    "Microsoft Office 2019",
    "Microsoft Office LTSC 2021",
    "Microsoft Office LTSC 2024"
  ],
  "cwes": [
    "CWE-807"
  ],
  "description": "Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.",
  "status": "Analyzed",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21509",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
