Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks

Microsoft released emergency out-of-band security updates on January 26, 2026, to address CVE-2026-21509, a zero-day security feature bypass vulnerability in Microsoft Office that attackers are actively exploiting. The flaw, rated “Important” with a CVSS v3.1 base score of 7.8, relies on untrusted inputs in security decisions to circumvent OLE mitigations protecting against vulnerable COM/OLE controls. […]

The post Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: