DNA View

⚠️ CISA Known Exploited Vulnerability

Active Threat

This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.

CVE-2026-21509

High CISA KEV
Low Medium High Critical
7.8
CVSS Score
Published: Jan 26, 2026
Last Modified: Feb 11, 2026

Vulnerability Description

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
L
Attack Complexity
L
Privileges Required
N
User Interaction
R
Scope
U
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

5 configuration(s) from 1 vendor(s)

office_long_term_servicing_channel
Version:
2024
CPE:
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*
office_long_term_servicing_channel
Version:
2021
CPE:
cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:*:x86:*
office
Version:
2016
CPE:
cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:*
office
Version:
2019
CPE:
cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:x64:*
365_apps
Version:
-
CPE:
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
This vulnerability affects 5 software configuration(s). Ensure you patch all affected systems.

Severity Details

7.8
out of 10.0
High

CISA KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog

Weakness Type (CWE)

CWE-807

Reliance on Untrusted Inputs in a Security Decision

Description
The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
Exploit Likelihood
High
Typical Severity
High
Abstraction Level
Base

Key Information

Published Date
January 26, 2026

Related News Articles

Latest news and updates about CVE-2026-21509