Summary
Microsoft Office has a security feature bypass in its OLE/COM handling. A crafted Office document can trick Office into trusting untrusted input and loading a COM or OLE object that should be blocked, which is useful in phishing-style attacks after a victim opens the file. In affected unpatched builds, this can enable malicious payload delivery and lead to code execution.
Why Planned Fix?
4/6Exploitation Details
Bypass Office security checks and load malicious COM/OLE content that can deliver code execution.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Microsoft Office 2016 | versions prior to 16.0.5539.1001 |
| Microsoft Office 2019 | versions prior to 16.0.10417.20095 |
| Microsoft Office LTSC 2021 | all supported versions |
| Microsoft Office LTSC 2024 | all supported versions |
| Microsoft 365 Apps for enterprise | all supported versions |
Desktop productivity suite for creating and editing documents, spreadsheets, presentations, email, and related Office file formats.
Affected ComponentOffice document security decision logic for linked or embedded OLE/COM objects in Word and related Office apps.
Office document security decision logic for linked or embedded OLE/COM objects in Word and related Office apps.
Use Microsoft's Office COM kill-bit / COM compatibility registry mitigation to block the vulnerable COM object until patching is complete.
Use Microsoft's Office COM kill-bit / COM compatibility registry mitigation to block the vulnerable COM object until patching is complete.
Not available
Install Microsoft's January 26, 2026 Office security update. Office 2016 needs KB5002713 and build 16.0.5539.1001 or later; Office 2019 needs build 16.0.10417.20095 or later. Microsoft 365 Apps and Office LTSC 2021/2024 receive a service-side fix and require an Office restart.
Install Microsoft's January 26, 2026 Office security update. Office 2016 needs KB5002713 and build 16.0.5539.1001 or later; Office 2019 needs build 16.0.10417.20095 or later. Microsoft 365 Apps and Office LTSC 2021/2024 receive a service-side fix and require an Office restart.
Probability of exploitation in the next 30 days
Worse than 92% of all CVEs
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Software (CPE) (10)
- •cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
- •cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
- •cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x64:*
- •cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:*
- •cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x64:*
- •cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x86:*
- •cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*
- •cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*
- •cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*
- •cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | NVD - CVE-2026-21509 Detail |
| msrc.microsoft.com | CVE-2026-21509 - Security Update Guide |
| support.microsoft.com | Description of the security update for Office 2016: January 26, 2026 (KB5002713) |
| support.microsoft.com | Security Settings for COM objects in Office |
| zscaler.com | Operation Neusploit: APT28 Uses CVE-2026-21509 |
| decalage.info | Posts | >> Decalage |
| tenable.com | CVE-2026-21509 Plugins |
Priority History
Initial analysis