CVE-2026-21509High· 7.8▾ Abyssal⚠ Exploited in the wild0dayPoC availableReliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 14.6 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Feb 16, 2026
Last analysed / modified upstream
72%
13 GitHub repos
72% → 73%
Added to the CISA catalog on Jan 26, 2026. Federal remediation due Feb 16, 2026. View catalog ↗
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
365_appsoffice = 2016office = 2019office_long_term_servicing_channel = 2021office_long_term_servicing_channel = 2024Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-42292High· 7.8Microsoft Excel Security Feature Bypass Vulnerability
CVE-2021-38646High· 7.8Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-85875Medium· 5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-83951Medium· 5.5Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.