Microsoft Rushes Emergency Fix For Actively Exploited Office Zero-Day post, januari 26, 2026januari 27, 2026 Microsoft has issued emergency, out-of-band security updates to address a high-severity zero-day vulnerability in Microsoft Office that is already being exploited in real-world attacks, underscoring the persistent security challenges facing one of the world’s most widely deployed productivity platforms. The flaw, tracked as CVE-2026-21509, is classified as a security feature bypass vulnerability and affects a broad range of Office products, including Microsoft Office 2016, Office 2019, Office LTSC 2021, Office LTSC 2024, and Microsoft 365 Apps for Enterprise. According to Microsoft, the vulnerability allows attackers to circumvent built-in protections designed to block unsafe COM and OLE controls—components that have long been a favored attack surface for malicious actors. (1) Microsoft Rushes Emergency Fix For Actively Exploited Office Zero-Day | LinkedIn: Microsoft Rushes Emergency Fix For Actively Exploited Office Zero-Day vulnerability 2026