Reliance on Untrusted Inputs in a Security Decision in Microsoft products - CVE-2026-21514
Published: February 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient mitigations for COM/OLE controls. A remote attacker can trick the victim into opening a specially crafted Word file, bypass implemented OLE mitigations and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Microsoft 365 Apps for Enterprise
Microsoft Office for macOS
How to mitigate CVE-2026-21514
Microsoft Office for macOS - update to 16.106.26020821 16.106.26020821