Reliance on Untrusted Inputs in a Security Decision in Microsoft Office - CVE-2026-21509
Published: January 26, 2026 / Updated: February 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper insecure handling of OLE objects. A remote attacker can trick the victim into opening a specially crafted Office file and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2026-21509
Install updates from vendor's website.
Note, at the moment Microsoft Office 2016 and 2019 do not have a security update. Microsoft is working to release it.
Links to Public Exploits and PoC-codes
- Exploit #12376 - CTT-NFS-Vortex-RCE (New Physics Disclosure This repository contains a full weaponized exploit for **CVE-2026-21509**, targeting the Windows Network File System (NFSv4.1) kernel-mode driver (`nfssvr.sys`). ) (February 6, 2026)
- Exploit #12371 - CTT-MICROSOFT-OFFICE-OLE-MANIFOLD-BYPASS-CVE-2026-21509 (CVE-2026-21509 is a critical bypass in the Microsoft Office OLE (Object Linking and Embedding) validation engine. While standard "laminar" exploits attempt to manipulate static COM objects, this rep (February 6, 2026)