Cyber Security News

Microsoft Office Word 0-day Vulnerability Actively Exploited in the Wild

A critical zero-day vulnerability in Microsoft Word, tracked as CVE-2026-21514, was disclosed on February 10, 2026, allowing attackers to bypass essential security protections.

This flaw has been actively exploited in the wild and carries a CVSS 3.1 base score of 7.8, with a temporal score of 7.2.

CVE-2026-21514 exploits a weakness in how Microsoft Word handles security decisions based on untrusted inputs, categorized as CWE-807.

The vulnerability specifically bypasses Object Linking and Embedding (OLE) mitigations implemented by Microsoft to protect users from malicious COM/OLE controls.

These OLE controls enable documents to embed and interact with external objects. However, improper validation allows attackers to circumvent protective measures.

MetricDetail
CVE IDCVE-2026-21514 ​
Vulnerability TypeSecurity Feature Bypass
Max SeverityImportant
WeaknessCWE-807: Reliance on Untrusted Inputs in a Security Decision ​
CVSS v3.1 Score7.8 ​
Vector StringCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Attack Vector and Exploitation Mechanics

The attack vector is classified as “Local” (AV:L) with low attack complexity (AC:L), requiring no privileges (PR: N) but necessitating user interaction (UI: R).

Attackers must craft a specially designed Office document and convince victims to open it through phishing emails or other social engineering methods.

The exploit scope is unchanged (S: U), meaning the vulnerable component doesn’t affect resources beyond its security scope.

Unlike traditional macro-based attacks that trigger security warnings, CVE-2026-21514 bypasses these protections entirely.

When users open malicious documents, the exploit executes without displaying “Enable Content” prompts or Protected View warnings that typically alert users to potential threats.

The exploit code maturity is rated as “Functional” (E: F), indicating working exploit code exists and has been deployed in real-world attacks.

The vulnerability affects multiple Office versions, including Microsoft 365 Apps for Enterprise (32-bit and 64-bit), Office LTSC 2021 and 2024 editions, and Office LTSC for Mac 2021 and 2024.

Microsoft released official fixes through Click-to-Run updates for Windows versions and version 16.106.26020821 for Mac systems.​

CISA mandated federal agencies patch this vulnerability by March 3, 2026, reflecting its severity.

Organizations should immediately deploy available security updates, implement email filtering to block suspicious Office documents, and educate users about opening unsolicited attachments.

Consider restricting OLE object execution through Group Policy settings until patches are applied.

Security researchers from Google Threat Intelligence Group and Microsoft’s internal security teams collaborated to identify and remediate this threat.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago