Story perspectives
Urgent: Microsoft Issues Patch for High-Risk Zero-Day Flaw
1/28/2026
1 of 1
Story summary
- CVE-2026-21509 is a high-risk zero-day in Office 2016–2024 and Microsoft 365 Apps.
- It lets attackers bypass security features and control COM/OLE by tricking users.
- Microsoft issued emergency updates, and Office 2021+ auto-updates, while Office 2016–2019 require manual updates.
- The U.S. Cybersecurity and Infrastructure Security Agency has added the flaw to the Known Exploited Vulnerabilities catalog, and federal patch is due by February 16, 2026.
