Microsoft Patches Office Zero-Day Likely Exploited in Targeted Attacks
CVE-2026-21509 is an Office zero-day that bypasses OLE mitigations and is actively exploited; Microsoft released patches and CISA added it to the KEV catalog.
Microsoft Office Zero-Day (CVE-2026-21509) - Emergency Patch Issued for Active Exploitation
Microsoft released out-of-band patches for an OLE mitigation bypass zero-day (CVE-2026-21509) in Office; Office 2021+ gets service-side protection after restart.