Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3596 articles · 106571 vulns · 38/41 feeds (7d)
← Back to list
7.8
CVE-2026-21509KEVEXPLOITED
microsoft · 365_apps

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Description

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Affected Products

VendorProductVersions
microsoft365_apps—

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509(Vendor Advisory)
  • https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability(Third Party Advisory)
  • https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability(Mitigation, Third Party Advisory)
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509(US Government Resource)

Related News (1 articles)

Tier D
The Hacker News6h ago
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-807
PublishedJan 26, 2026
Last enriched7d ago
Trending Score94
Source articles1
Independent1
Info Completeness9/14
Missing: versions, epss, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-21513EXPKEV
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
Trending: 94
CRITICALCVE-2026-32213EXP
Azure AI Foundry Elevation of Privilege Vulnerability
Trending: 67
CRITICALCVE-2026-32211EXP
Azure MCP Server Information Disclosure Vulnerability
Trending: 67
HIGHCVE-2026-32173EXP
Azure SRE Agent Information Disclosure Vulnerability
Trending: 60
CRITICALCVE-2026-33107
Azure Databricks Elevation of Privilege Vulnerability
Trending: 53

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jan 26, 2026
Added to CISA KEV
Jan 26, 2026
Actively Exploited
Feb 11, 2026
Exploit Available
Feb 11, 2026
Discovered by ZDM
Apr 1, 2026