Microsoft issues emergency Office update to fix zero-day flaw
bangkokpost.com·5h
💻Microsoft
Preview
Report Post

Microsoft has released an out-of-band emergency security update to address a zero-day vulnerability in Microsoft Office that is being actively exploited, extending support for affected versions through 2026.

The vulnerability, tracked as CVE-2026-21509, carries a high severity score of 7.8 out of 10. It is classified as a security feature bypass flaw that allows attackers to evade Office’s Object Linking and Embedding (OLE) protections.

According to Microsoft, the flaw arises because Office improperly trusts certain embedded data that can contain malicious code. This enables attackers to bypass built-in security mechanisms and potentially execute harmful actions on a victim’s system.

Exploitation occurs when a user opens a specially crafted Office file sent by an attacker, such …

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help