#VU122540 Reliance on Untrusted Inputs in a Security Decision in Microsoft products - CVE-2026-21514

 

#VU122540 Reliance on Untrusted Inputs in a Security Decision in Microsoft products - CVE-2026-21514

Published: February 10, 2026


Vulnerability identifier: #VU122540
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2026-21514
CWE-ID: CWE-807
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Microsoft Office
Microsoft Office for macOS
Microsoft 365 Apps for Enterprise
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient mitigations for COM/OLE controls. A remote attacker can trick the victim into opening a specially crafted Word file, bypass implemented OLE mitigations and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild. 


Remediation

Install updates from vendor's website.

External links