216.73.217.22

CVE-2026-21509

· Published 26/01/2026 01:00 · Modified 27/03/2026 01:01 · Author: The MITRE Corporation

Labels: CVE-2026-21509 2026-01-26CVE-2026-21509CWE-807[email protected]

Essential information

Published
26/01/2026 01:00
Modified
27/03/2026 01:01
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
7.8 HIGH (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:L/C:H/I:H/A:H

CVSS metrics

Description

Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
microsoft / 365 apps cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
microsoft / 365 apps cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
microsoft / office cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x64:*
microsoft / office cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:*
microsoft / office cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x64:*
microsoft / office cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x86:*
microsoft / office long term servicing channel cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*
microsoft / office long term servicing channel cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*
microsoft / office long term servicing channel cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*
microsoft / office long term servicing channel cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*

References