{"id":"CVE-2026-21509","title":"Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.","summary":"Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-807"],"vendor":"microsoft","product":"365_apps","affected":["365_apps","office = 2016","office = 2019","office_long_term_servicing_channel = 2021","office_long_term_servicing_channel = 2024"],"published":"2026-01-26","updated":"2026-06-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-21509","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509","label":"secure@microsoft.com"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.72872,"epssPercentile":0.99434,"kev":true,"kevDateAdded":"2026-01-26","kevDueDate":"2026-02-16","kevRansomware":false,"exploited":true,"zeroDay":true,"ingestedAt":"2026-06-29T13:24:34.633Z","exploits":{"github":13,"githubRepos":["https://github.com/kimstars/Ashwesker-CVE-2026-21509","https://github.com/gavz/CVE-2026-21509-PoC","https://github.com/ksk-itdk/KSK-ITDK-CVE-2026-21509-Mitigation"],"checkedAt":"2026-09-25T08:20:52.886Z"},"exploitAvailable":true,"slug":"CVE-2026-21509","body":"## Overview\n\nReliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.\n\n## Affected\n\n- `365_apps`\n- `office = 2016`\n- `office = 2019`\n- `office_long_term_servicing_channel = 2021`\n- `office_long_term_servicing_channel = 2024`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":82,"depthScoreParts":{"impact":42.9,"likelihood":14.6,"exploitation":25,"ransomware":0},"changes":[{"seq":5006,"id":"CVE-2026-21509","ts":1788887227822,"field":"exploit_available","old":"false","new":"true"},{"seq":3889,"id":"CVE-2026-21509","ts":1788886358755,"field":"exploit_available","old":"true","new":"false"},{"seq":2711,"id":"CVE-2026-21509","ts":1788883024448,"field":"exploit_available","old":"false","new":"true"},{"seq":1740,"id":"CVE-2026-21509","ts":1788882428464,"field":"exploit_available","old":"true","new":"false"},{"seq":846,"id":"CVE-2026-21509","ts":1788881861745,"field":"exploit_available","old":"false","new":"true"}]}