#VU122047 Reliance on Untrusted Inputs in a Security Decision in Microsoft Office - CVE-2026-21509
Published: January 26, 2026 / Updated: February 6, 2026
Microsoft Office
Microsoft
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper insecure handling of OLE objects. A remote attacker can trick the victim into opening a specially crafted Office file and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install updates from vendor's website.
Note, at the moment Microsoft Office 2016 and 2019 do not have a security update. Microsoft is working to release it.