<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Microsoft Patches Actively Exploited Office Zero-Day Vulnerability

Microsoft issues emergency patch for CVE-2026-21509, a zero-day in Office exploited via phishing. Update now for protection.
Content Team

Microsoft rushed out emergency security updates on January 26, 2026, to fix CVE-2026-21509, a zero-day vulnerability in Microsoft Office that hackers are actively exploiting. The flaw lets attackers bypass Office security protections by tricking users into opening malicious files through phishing emails.

Rated "Important" with a 7.8 severity score, the vulnerability affects multiple Office versions including 2016, 2019, 2021, and Microsoft 365. Office 2021 and newer versions get automatic protection after restarting, while older versions need manual updates or registry modifications.

This marks the second actively exploited zero-day patched this month. Organizations should prioritize installing these updates immediately and watch for suspicious Office attachments, as threat actors commonly use this attack method for ransomware and advanced persistent threat campaigns.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo