Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Exploring the closed nuclear fuel cycle: From recycling to fuel

Unmasking new TOAD attacks hidden in legitimate infrastructure

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Microsoft Office Zero Day (CVE-2026-21509) – Emergency patch issued for active exploit
Identity

Microsoft Office Zero Day (CVE-2026-21509) – Emergency patch issued for active exploit

userBy userJanuary 27, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananJanuary 27, 2026Zero-day/vulnerabilities

Microsoft on Monday issued an out-of-band security patch for a high-severity zero-day vulnerability in Microsoft Office that was exploited in the attack.

This vulnerability is tracked as CVE-2026-21509 and has a CVSS score of 7.8 out of 10.0. This is described as a bypass of Microsoft Office security features.

“Microsoft Office’s reliance on untrusted input in security decisions may allow an unauthorized attacker to locally bypass security features,” the tech giant said in an advisory.

“This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office that protect users from vulnerable COM/OLE controls.”

Successful exploitation of this flaw relies on an attacker sending a specially crafted Office file and persuading the recipient to open the file. We also mentioned that the preview pane is not an attack vector.

cyber security

The Windows maker said customers running Office 2021 or newer will be automatically protected by the service-side change, but they will need to restart their Office applications for it to take effect. If you’re running Office 2016 and 2019, you should install the following updates:

Microsoft Office 2019 (32-bit version) – 16.0.10417.20095 Microsoft Office 2019 (64-bit version) – 16.0.10417.20095 Microsoft Office 2016 (32-bit version) – 16.0.5539.1001 Microsoft Office 2016 (64-bit version) – 16.0.5539.1001

As a mitigation measure, the company recommends customers modify the Windows registry by following the steps outlined below.

Create a backup of the registry Exit all Microsoft Office applications Launch Registry Editor Locate the appropriate registry subkey – HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\ for 64-bit MSI Office, 32-bit MSI Office 32 on 64-bit Windows HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Office\16.0\Common\COM Compatibility\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Office\16.0\Common\COM Compatibility\ (64 Click2Run Office for 32-bit Click2Run Office on 64-bit Windows Add a new subkey named {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}. Right-click the COM Compatibility node and[キーの追加]Select. Within that subkey, right-click the new subkey,[新規]>[DWORD (32 ビット) 値]Select to add a new value. Add a REG_DWORD hex value named “Compatibility Flag” with value 400. Exit Registry Editor and start the Office application.

cyber security

Microsoft has not provided details regarding the nature and scope of the attack leveraging CVE-2026-21509. The Microsoft Threat Intelligence Center (MSTIC), Microsoft Security Response Center (MSRC), and the Office Product Group security team are credited with discovering this issue.

Following this development, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog and required Federal Civilian Executive Branch (FCEB) agencies to patch it by February 16, 2026.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMeta for testing premium subscriptions on Instagram, Facebook, and WhatsApp
Next Article Sonic booms offer new way to track falling space debris
user
  • Website

Related Posts

Unmasking new TOAD attacks hidden in legitimate infrastructure

January 28, 2026

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

January 28, 2026

WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

January 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Exploring the closed nuclear fuel cycle: From recycling to fuel

Unmasking new TOAD attacks hidden in legitimate infrastructure

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Everything you need to know about the viral personal AI assistant Clawdbot (now Moltbot)

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.