CVE-2026-21509
HIGH KEVMicrosoft Office - Info Disclosure
Title source: llmDescription
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Exploits (13)
github
WORKING POC
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-21509
nomisec
WORKING POC
3 stars
by SimoesCTT · poc
https://github.com/SimoesCTT/CTT-MICROSOFT-OFFICE-OLE-MANIFOLD-BYPASS-CVE-2026-21509
nomisec
WORKING POC
1 stars
by SimoesCTT · poc
https://github.com/SimoesCTT/SCTT-2026-33-0007-The-OLE-Vortex-Laminar-Bypass-
nomisec
SCANNER
1 stars
by ksk-itdk · poc
https://github.com/ksk-itdk/KSK-ITDK-CVE-2026-21509-Mitigation
References (4)
Scores
CVSS v3
7.8
EPSS
0.1086
EPSS Percentile
93.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2026-01-26
VulnCheck KEV
2026-01-26
ENISA EUVD
EUVD-2026-4666
CWE
CWE-807
Status
published
Products (10)
microsoft/365_apps
(2 CPE variants)
Microsoft/Microsoft 365 Apps for Enterprise
16.0.1 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office 2016
16.0.0 - 16.0.5539.1001
Microsoft/Microsoft Office 2019
19.0.0 - 16.0.10417.20095
Microsoft/Microsoft Office LTSC 2021
16.0.1 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office LTSC 2024
16.0.0 - https://aka.ms/OfficeSecurityReleases
microsoft/office
2016 (2 CPE variants)
microsoft/office
2019 (2 CPE variants)
microsoft/office_long_term_servicing_channel
2021 (2 CPE variants)
microsoft/office_long_term_servicing_channel
2024 (2 CPE variants)
Published
Jan 26, 2026
KEV Added
Jan 26, 2026
Tracked Since
Feb 18, 2026