← Back

CVE-2026-21509

nvd nist
Published: Jan 26, 2026Modified: Feb 11, 2026CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Affected (10)

3 products
365 Apps
Office
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
All versions
Microsoft
Version 2016
Version 2016
Version 2019
Version 2019
Microsoft
Version 2021
Version 2021
Version 2024
Version 2024

Timeline

No history available yet.