#VU122047 Reliance on Untrusted Inputs in a Security Decision in Microsoft Office - CVE-2026-21509
Published: January 26, 2026
Vulnerability identifier: #VU122047
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2026-21509
CWE-ID: CWE-807
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerable software:
Microsoft Office
Microsoft Office
Software vendor:
Microsoft
Microsoft
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper insecure handling of OLE objects. A remote attacker can trick the victim into opening a specially crafted Office file and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install updates from vendor's website.
Note, at the moment Microsoft Office 2016 and 2019 do not have a security update. Microsoft is working to release it.