HIGH
CVE-2026-21509
CVSS
7.8
KEV
Description
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Summary dbcve.org
This vulnerability in Microsoft Office allows an attacker to bypass a security feature locally by exploiting untrusted inputs in a security decision. The flaw enables an unauthorized user to circumvent security controls through improper validation of input data used in access control or security policy enforcement.
Mitigation
Apply Microsoft security updates for Office when available; verify security feature configurations are working as intended and not being bypassed through unvalidated input paths.
Weakness (CWE)
CWE-807
EPSS Score
72.55%
Probability of exploitation in next 30 days
99.4th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
Vendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-21509-detection-script-microsoft-office-security-feature-bypass-vulnerability
Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2026-21509-mitigation-script-microsoft-office-security-feature-bypass-vulnerability
Mitigation, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21509
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.