HIGH

CVE-2026-21514

Microsoft 365 Apps 2026-02-10 CVSS v3.1
CVSS
7.8
KEV

Description

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

Summary dbcve.org

This is a local security feature bypass vulnerability in Microsoft Office Word where the software relies on untrusted inputs when making security decisions. An attacker with local access could potentially bypass a security mechanism by manipulating untrusted input data.

Mitigation

Apply the latest Microsoft Office Word security updates to address this vulnerability, and ensure security features that were bypassed are re-validated after patching.

Weakness (CWE)

CWE-807

EPSS Score

1.54%
Probability of exploitation in next 30 days
73.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE