Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html
https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html
https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html
https://therecord.media/russian-hackers-microsoft-office-europe
https://www.securityweek.com/russias-apt28-rapidly-weaponizes-newly-patched-office-vulnerability/
https://therecord.media/russian-state-hackers-exploit-new-microsoft-flaw
https://thehackernews.com/2026/02/apt28-uses-microsoft-office-cve-2026.html
https://hackread.com/op-neusploit-russia-apt28-microsoft-office-malware/
https://www.theregister.com/2026/02/02/russialinked_apt28_microsoft_office_bug/
https://www.infosecurity-magazine.com/news/fancy-bear-exploits-office-flaw/
https://blog.talosintelligence.com/microsoft-oob-update-january-2026/
https://www.theregister.com/2026/01/27/office_zeroday_exploited_in_the/
https://www.securityweek.com/microsoft-patches-office-zero-day-likely-exploited-in-targeted-attacks/
https://www.infosecurity-magazine.com/news/microsoft-patch-office-zero-day/
https://thehackernews.com/2026/01/microsoft-issues-emergency-patch-for.html
https://github.com/YoussefMami/CVE2026_21509
https://github.com/suuhm/CVE-2026-21509-handler
https://github.com/planetoid/cve-2026-21509-mitigation
https://github.com/decalage2/detect_CVE-2026-21509
https://github.com/SimoesCTT/CTT-MICROSOFT-OFFICE-OLE-MANIFOLD-BYPASS-CVE-2026-21509
https://github.com/XiaomingX/data-cve-poc-py-v1
https://github.com/rtbrown88-cmyk/CVE-Aura-Audit-2026
https://github.com/SimoesCTT/SCTT-2026-33-0007-The-OLE-Vortex-Laminar-Bypass-
https://github.com/SimoesCTT/CTT-NFS-Vortex-RCE
https://github.com/ksk-itdk/KSK-ITDK-CVE-2026-21509-Mitigation
https://github.com/nicole2ilodl/CVE-2026-21509-PoC
https://github.com/Ashwesker/Ashwesker-CVE-2026-21509
https://github.com/Hatchepsoute/sigma-rules
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509
Published: 2026-01-26
Updated: 2026-06-25
Known Exploited Vulnerability (KEV)
Base Score: 7.2
Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.72554
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest