INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Microsoft Office Zero-Day Exploit Patch Released

| 2026-01-29 14:43 CRITICAL HIGH
Executive Summary AI-generated
The recent release of a critical update to Microsoft Office has sparked widespread concern among cybersecurity experts and users alike. The vulnerability, CVE-2026-21509, was identified as an over-reliance on untrusted inputs in the security decision for Microsoft Office 365 and Microsoft Office applications. This flaw enables attackers to bypass object linking and embedding (OLE) mitigations, which protect users from vulnerable component object model (COM) and OLE controls. The update has been released as part of the standard Microsoft Patch Tuesday process, with three out-of-band updates already published in January 2026. As a result, Cisco Security Firewall customers are advised to use the latest update to their ruleset by updating their SRU. Additionally, Snort2 rules and ClamAV signature have been made available to detect activity associated with this vulnerability. The Microsoft Office team has also released mitigation guidance for CVE-2026-21509 as part of an advisory.
Technical Mitigations AI-generated
* Use secure protocols (HTTPS) when accessing Microsoft Office or other affected software to prevent exploitation of the zero-day vulnerability. * Implement a patch management strategy that includes regular updates and patches for all versions of Microsoft Office, including those running LTSC 2021 and later. * Configure security controls such as firewalls, intrusion detection systems, and antivirus software to detect and block attempts to exploit the zero-day vulnerability. * Educate users about the risks associated with exploiting this vulnerability and provide guidance on how to protect themselves, such as avoiding opening malicious Office files or using alternative methods for accessing Microsoft Office.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-21509CVE-2026-21509
Target & Sectors
Global Scope
Incident Timeline
January 2026
Microsoft released an update to address a zero-day vulnerability in Microsoft Office.
organisation OOB
infrastructure Microsoft Office
organisation Microsoft Patch
organisation Cisco Security Firewall
organisation SRU
organisation ClamAV
January 26
Microsoft released a patch for the zero-day vulnerability in Microsoft Office on January 26.
infrastructure Microsoft Office
vulnerability CVE-2026-21509
vulnerability CVSS 3.1
general_metric 3.1 score
Jan 27, 2026
Microsoft released an update to address a zero-day vulnerability in Microsoft Office.
Jan 27
Microsoft released an update to address a zero-day vulnerability in Microsoft Office.
infrastructure Microsoft Office
organisation Microsoft
2016, 2019
Microsoft releases update to address zero-day vulnerability in Microsoft Office 2016.
infrastructure Microsoft 365
general_metric 365 Microsoft
infrastructure Microsoft Office 2016
organisation LTSC 2021
organisation LTSC 2024
general_metric 2021 LTSC
general_metric 2024 LTSC
2026-01-29
Microsoft Releases Patch for Office Zero Day As mitigation, the company is urging that customers make a Windows Registry change by following the steps outlined below.
organisation Microsoft Office
organisation CVSS
organisation DWORD
organisation Exit Registry
organisation Reliance
organisation Microsoft 365
organisation OLE
infrastructure Windows
infrastructure 16.0
organisation Windows Registry
organisation the Registry Exit
organisation Compatibility\
organisation MSI Office
organisation Click2Run Office
organisation Microsoft
infrastructure Microsoft Office 2019
infrastructure Microsoft Office 2016
infrastructure 16.0.10417
infrastructure 16.0.5539
organisation Office
February 16, 2026
Microsoft released an update to address a zero-day vulnerability in Microsoft Office.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
​Microsoft Office
Affected Product
Metrics
infrastructure
​Microsoft 365
Affected Product
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​Microsoft Office 2019
Affected Product
Metrics
infrastructure
​Microsoft Office 2016
Affected Product
Metrics
infrastructure
​16.0.10417
Software Version
Metrics
infrastructure
​16.0.5539
Software Version
Metrics
infrastructure
​16.0
Software Version