Reliance on Untrusted Inputs in a Security Decision in Microsoft products - CVE-2026-21514

 

Reliance on Untrusted Inputs in a Security Decision in Microsoft products - CVE-2026-21514

Published: February 10, 2026


Vulnerability identifier: #VU122540
CSH Severity: Critical
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21514
CWE-ID: CWE-807
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient mitigations for COM/OLE controls. A remote attacker can trick the victim into opening a specially crafted Word file, bypass implemented OLE mitigations and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild. 


Affected software

Microsoft Office
Microsoft 365 Apps for Enterprise
Microsoft Office for macOS

How to mitigate CVE-2026-21514

Install updates from vendor's website.

Microsoft 365 Apps for Enterprise - update to 16.0.19725.20058
Microsoft Office for macOS - update to 16.106.26020821 16.106.26020821

External References

Related Security Bulletins