CVE-2026-21509Active Exploitation(microsoft / 365_apps)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 114 mentions and remains active

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-807

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office
  • office_long_term_servicing_channel

Threat summary

  • Active exploitation appears in 436 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 602 mentions across 85 observed days

What's happening

  • Active exploitation reported across 436 signals
  • Exploit tool or code specified in 48 signals
  • PoC mentioned or linked in 45 signals
  • Patch or workaround mentioned in 237 signals
  • Technical details provided in 181 signals
  • General: 81 classified signals
  • Peaked 77d ago at 114 mentions (2026-02-03); latest day: 1
  • 602 total mentions across 85 days

Affected systems

Vendors
Products
365_appsofficeoffice_long_term_servicing_channel

5 versions affected across 3 products

Deep dive

Activity timeline602 mentions / 85d
0295786114Mentions · 2026-01-27: 29Mentions · 2026-01-28: 52Mentions · 2026-01-29: 27Mentions · 2026-01-30: 9Mentions · 2026-01-31: 6Mentions · 2026-02-01: 9Mentions · 2026-02-02: 54Mentions · 2026-02-03: 114Mentions · 2026-02-04: 55Mentions · 2026-02-05: 31Mentions · 2026-02-06: 31Mentions · 2026-02-07: 9Mentions · 2026-02-08: 20Mentions · 2026-02-09: 14Mentions · 2026-02-10: 11Mentions · 2026-02-11: 5Mentions · 2026-02-12: 3Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-02-15: 3Mentions · 2026-02-16: 2Mentions · 2026-02-17: 1Mentions · 2026-02-19: 2Mentions · 2026-02-20: 6Mentions · 2026-02-22: 1Mentions · 2026-02-24: 2Mentions · 2026-02-25: 3Mentions · 2026-02-27: 3Mentions · 2026-02-28: 1Mentions · 2026-03-01: 3Mentions · 2026-03-02: 5Mentions · 2026-03-03: 2Mentions · 2026-03-04: 1Mentions · 2026-03-05: 2Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 3Mentions · 2026-03-12: 5Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-20: 1Mentions · 2026-03-22: 2Mentions · 2026-03-24: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 4Mentions · 2026-03-30: 3Mentions · 2026-03-31: 1Mentions · 2026-04-01: 3Mentions · 2026-04-02: 2Mentions · 2026-04-03: 2Mentions · 2026-04-04: 1Mentions · 2026-04-05: 2Mentions · 2026-04-06: 1Mentions · 2026-04-08: 8Mentions · 2026-04-09: 2Mentions · 2026-04-11: 1Mentions · 2026-04-13: 2Mentions · 2026-04-14: 1Mentions · 2026-04-16: 1Mentions · 2026-04-21: 1Mentions · 2026-04-24: 2Mentions · 2026-05-01: 2Mentions · 2026-05-07: 2Mentions · 2026-05-08: 1Mentions · 2026-05-24: 1Mentions · 2026-05-27: 1Mentions · 2026-06-02: 1Mentions · 2026-06-22: 1Mentions · 2026-07-02: 1Mentions · 2026-07-09: 1Mentions · 2026-07-21: 1Mentions · 2026-07-31: 2Mentions · 2026-08-03: 2Mentions · 2026-08-04: 1Mentions · 2026-08-06: 1Mentions · 2026-08-11: 2Mentions · 2026-08-12: 1Mentions · 2026-08-13: 1Mentions · 2026-09-07: 1Mentions · 2026-09-10: 1Mentions · 2026-09-11: 2Mentions · 2026-09-29: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-01-30: 1PoC Mentioned / Linked · 2026-01-31: 2PoC Mentioned / Linked · 2026-02-02: 3PoC Mentioned / Linked · 2026-02-03: 5PoC Mentioned / Linked · 2026-02-04: 3PoC Mentioned / Linked · 2026-02-05: 1PoC Mentioned / Linked · 2026-02-08: 2PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-02-20: 1PoC Mentioned / Linked · 2026-02-24: 2PoC Mentioned / Linked · 2026-03-01: 1PoC Mentioned / Linked · 2026-03-02: 1PoC Mentioned / Linked · 2026-03-11: 1PoC Mentioned / Linked · 2026-03-12: 4PoC Mentioned / Linked · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-27: 2PoC Mentioned / Linked · 2026-03-31: 1PoC Mentioned / Linked · 2026-04-01: 2PoC Mentioned / Linked · 2026-04-04: 1PoC Mentioned / Linked · 2026-04-13: 2PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-21: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-07-02: 1PoC Mentioned / Linked · 2026-07-09: 1PoC Mentioned / Linked · 2026-08-03: 1Exploit Tool / Code · 2026-01-27: 1Exploit Tool / Code · 2026-01-29: 1Exploit Tool / Code · 2026-02-02: 6Exploit Tool / Code · 2026-02-03: 11Exploit Tool / Code · 2026-02-04: 2Exploit Tool / Code · 2026-02-05: 2Exploit Tool / Code · 2026-02-06: 4Exploit Tool / Code · 2026-02-07: 1Exploit Tool / Code · 2026-02-09: 2Exploit Tool / Code · 2026-02-10: 1Exploit Tool / Code · 2026-02-20: 1Exploit Tool / Code · 2026-02-24: 1Exploit Tool / Code · 2026-02-25: 1Exploit Tool / Code · 2026-03-02: 1Exploit Tool / Code · 2026-03-11: 2Exploit Tool / Code · 2026-03-12: 2Exploit Tool / Code · 2026-03-20: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-04-01: 1Exploit Tool / Code · 2026-04-04: 1Exploit Tool / Code · 2026-04-09: 1Exploit Tool / Code · 2026-04-13: 1Exploit Tool / Code · 2026-04-14: 1Exploit Tool / Code · 2026-05-07: 1Exploit Tool / Code · 2026-07-09: 1Active Exploitation · 2026-01-27: 24Active Exploitation · 2026-01-28: 35Active Exploitation · 2026-01-29: 15Active Exploitation · 2026-01-30: 5Active Exploitation · 2026-01-31: 5Active Exploitation · 2026-02-01: 4Active Exploitation · 2026-02-02: 39Active Exploitation · 2026-02-03: 101Active Exploitation · 2026-02-04: 44Active Exploitation · 2026-02-05: 27Active Exploitation · 2026-02-06: 22Active Exploitation · 2026-02-07: 5Active Exploitation · 2026-02-08: 12Active Exploitation · 2026-02-09: 12Active Exploitation · 2026-02-10: 11Active Exploitation · 2026-02-11: 4Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-15: 3Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-02-20: 4Active Exploitation · 2026-02-25: 2Active Exploitation · 2026-02-27: 1Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-03-02: 2Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-11: 3Active Exploitation · 2026-03-12: 5Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-22: 2Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-30: 2Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-04-01: 2Active Exploitation · 2026-04-02: 1Active Exploitation · 2026-04-03: 2Active Exploitation · 2026-04-04: 1Active Exploitation · 2026-04-05: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-08: 6Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-05-01: 2Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-06-22: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-07-31: 2Active Exploitation · 2026-08-03: 1Active Exploitation · 2026-08-11: 2Active Exploitation · 2026-08-12: 1Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-09-07: 1Patch / Workaround · 2026-01-27: 26Patch / Workaround · 2026-01-28: 40Patch / Workaround · 2026-01-29: 18Patch / Workaround · 2026-01-30: 8Patch / Workaround · 2026-01-31: 4Patch / Workaround · 2026-02-01: 6Patch / Workaround · 2026-02-02: 19Patch / Workaround · 2026-02-03: 42Patch / Workaround · 2026-02-04: 23Patch / Workaround · 2026-02-05: 10Patch / Workaround · 2026-02-06: 6Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-08: 5Patch / Workaround · 2026-02-09: 2Patch / Workaround · 2026-02-10: 3Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-15: 2Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 2Patch / Workaround · 2026-03-01: 1Patch / Workaround · 2026-03-02: 2Patch / Workaround · 2026-03-03: 2Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-05: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-24: 2Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-09-07: 1Patch / Workaround · 2026-09-11: 1Technical Details · 2026-01-27: 9Technical Details · 2026-01-28: 24Technical Details · 2026-01-29: 9Technical Details · 2026-01-30: 3Technical Details · 2026-01-31: 4Technical Details · 2026-02-01: 4Technical Details · 2026-02-02: 19Technical Details · 2026-02-03: 25Technical Details · 2026-02-04: 15Technical Details · 2026-02-05: 6Technical Details · 2026-02-06: 5Technical Details · 2026-02-07: 1Technical Details · 2026-02-08: 8Technical Details · 2026-02-09: 3Technical Details · 2026-02-10: 7Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 1Technical Details · 2026-02-15: 2Technical Details · 2026-02-19: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-30: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-05: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-24: 1Technical Details · 2026-05-07: 2Technical Details · 2026-05-08: 1Technical Details · 2026-07-31: 1Technical Details · 2026-08-03: 2Technical Details · 2026-08-04: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-11: 2Technical Details · 2026-08-12: 1Technical Details · 2026-08-13: 1Technical Details · 2026-09-07: 1Technical Details · 2026-09-10: 101-2702-0402-1202-2203-0403-1603-3104-0905-0707-2109-0709-30
Signal classification9 categories
Active Exploitation
37863.0%
Patch
8814.7%
General
8113.5%
Disclosure
213.5%
Exploit
172.8%
PoC
111.8%
Referenced assets410 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-2729
Active Exploitation14Activeoitation1Disclosure1Patch13
2026-01-2852
Active Exploitation18Disclosure4Exploit1General6Patch23
2026-01-2927
Active Exploitation7Exploit1General5Patch14
2026-01-309
Active Exploitation5General1Patch3
2026-01-316
Active Exploitation2General1Patch2PoC1
2026-02-019
Active Exploitation3General2Patch4
2026-02-0254
Active Exploitation37Disclosure2False Positive2General7Patch4PoC2
2026-02-03114
Active Exploitation96Exploit3General10Patch4PoC1
2026-02-0455
Active Exploitation41General7Patch5PoC2
2026-02-0531
Active Exploitation26Disclosure1General3Patch1
2026-02-0631
Active Exploitation21Disclosure3Exploit1General6
2026-02-079
Active Exploitation5General4
2026-02-0820
Active Exploitation12Disclosure2General4Patch1PoC1
2026-02-0914
Active Exploitation12General2
2026-02-1011
Active Exploitation9Exploit1Patch1
2026-02-115
Active Exploitation4General1
2026-02-123
Active Exploitation1General2
2026-02-131
Active Exploitation1
2026-02-141
General1
2026-02-153
Active Exploitation2Patch1
2026-02-162
Active Exploitation1General1
2026-02-171
General1
2026-02-192
General1Patch1
2026-02-206
Active Exploitation4General1Patch1
2026-02-221
General1
2026-02-242
Exploit1PoC1
2026-02-253
Active Exploitation2General1
2026-02-273
Active Exploitation1General2
2026-02-281
Active Exploitation1
2026-03-013
Exploit1General1Patch1
2026-03-025
Active Exploitation2General2Patch1
2026-03-032
Active Exploitation1Patch1
2026-03-041
Active Exploitation1
2026-03-052
Active Exploitation1Disclosure1
2026-03-091
Disclosure1
2026-03-101
Active Exploitation1
2026-03-113
Active Exploitation3
2026-03-125
Active Exploitation5
2026-03-131
Active Exploitation1
2026-03-141
Active Exploitation1
2026-03-161
Disclosure1
2026-03-171
Active Exploitation1
2026-03-201
Active Exploitation1
2026-03-222
Active Exploitation2
2026-03-241
Active Exploitation1
2026-03-261
General1
2026-03-274
Active Exploitation1Disclosure1Exploit1PoC1
2026-03-303
Active Exploitation2Disclouser1
2026-03-311
Exploit1
2026-04-013
Active Exploitation2Exploit1
2026-04-022
Active Exploitation1General1
2026-04-032
Active Exploitation2
2026-04-041
Exploit1
2026-04-052
Active Exploitation1Patch1
2026-04-061
Active Exploitation1
2026-04-088
Active Exploitation6Disclosure1Patch1
2026-04-092
Active Exploitation1General1
2026-04-111
Disclosure1
2026-04-132
Exploit1PoC1
2026-04-141
Exploit1
2026-04-161
General1
2026-04-211
Active Exploitation1
2026-04-242
Patch2
2026-05-012
Active Exploitation2
2026-05-072
Active Exploitation1Disclosure1
2026-05-081
Active Exploitation1
2026-05-241
General1
2026-05-271
Active Exploitation1
2026-06-021
General1
2026-06-221
Active Exploitation1
2026-07-021
Active Exploitation1
2026-07-091
Exploit1
2026-07-211
Patch1
2026-07-312
Active Exploitation2
2026-08-032
Active Exploitation1PoC1
2026-08-041
Disclosure1
2026-08-061
Exploit1
2026-08-112
Active Exploitation2
2026-08-121
Active Exploitation1
2026-08-131
Active Exploitation1
2026-09-071
Patch1
2026-09-101
General1
2026-09-112
General1Patch1
Full discourse20 posts
  • CERT-UA@_CERT_UA
    Active Exploitation

    UAC-0001 (aka #APT28 or #FancyBear) exploits CVE-2026-21509 to target Ukraine and EU with COVENANT framework. Details (UA only): https://cert.gov.ua/article/6287250 https://t.co/oYPBtsn0cD

    Post summary

    The post reports that UAC‑0001 (APT28/FancyBear) is actively exploiting CVE‑2026‑21509 with the COVENANT framework to target Ukraine and EU. No PoC, patch, or technical details are provided.

    265324510745.6K
    2.5K followersView on X
  • Haifei Li@HaifeiLi
    PoC

    Someone submitted the real CVE-2026-21509 sample to EXPMON last night! Check out this submission: https://pub.expmon.com/analysis/311631/ The SHA256 of the sample, it's a RTF file: c91183175ce77360006f964841eb4048cf37cb82103f2573e262927be4c7607f While EXPMON didn't report the 0day immediately - this is well expected, it reported various highly suspicious Indicators, including the key Indicator named "activex compatibility shellexplorer registry key accessed". I shared how to use this key Indicator on EXPMON to hunt the 0day just days ago: https://x.com/HaifeiLi/status/2016340091505906035. That's enough to investigate it manually in your local env, and I have just confirmed this is indeed the CVE-2026-21509 zero-day exploit! My quick analysis showed that this is the initial attack vector sample in a full attacking chain. Thanks to EXPMON logs, I quickly found that the RTF file was trying to load the IE engine (the "ieframe.dll") while also trying to connect to the threat actor controlled server, one of the url is "\\wellnesscaremed[.]com\davwwwroot\venezia\Favorites\blank.doc" (see the pic attached) - all activities are automatic, meaning as soon as the victim open the Word document, the victim could be pwned. There're not just one but quite serveral OLE objects in the RTF which are, to be honest, quite sophisticated, showing the sophistication of the zero-day attack. Full details haven't been fully understood in such a short time. The same sample was also listed/confirmed by the Ukrainian CERT https://cert.gov.ua/article/6287250 independently, there're more details in that article please go check out. What a wild story! Thank you very much to the person who submitted the sample (and I received your message about adding the "unzip" feature:))! Once again it confirmed the effectiveness of the EXPMON system when it comes to detecting unknown 0day exploits. Quickly, for defenders: 1. Please research all the things starting from the sample, this is the confirmed CVE-2026-21509 0day intinal attack vector sample, and add detections (currently the detection ratio on VT is pretty low) in the full chain. 2. If you're an Microsoft Office user, please apply Microsoft's official patch or workarounds ASAP https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509, as now the attacking exploit is well known so attacks are expected to increase rapidly. For me, there's more work to do, including an EXPMON update for determinate detection against this 0day exploits. In the meantime, if you see the "activex compatibility shellexplorer registry key accessed" Indicator on EXPMON, please be cautions because that's likely the 0day sample/variants. #CVE-2026-21509 #expmon #0day #zeroday #exploit #threatintel

    Post summary

    A real sample of CVE‑2026‑21509 was submitted and analyzed, confirming a zero‑day exploit that uses an RTF payload to load IE's engine and connect to a remote server. Defenders are urged to add detection rules and apply Microsoft’s patch immediately.

    356222012729.2K
    8.3K followersView on X
  • Steven Lim@0x534c
    Patch

    🔥𝗗𝗲𝗳𝗲𝗻𝗱𝗶𝗻𝗴 𝗔𝗴𝗮𝗶𝗻𝘀𝘁 𝗖𝗩𝗘‑𝟮𝟬𝟮𝟲‑𝟮𝟭𝟱𝟬𝟵: 𝗖𝗿𝗶𝘁𝗶𝗰𝗮𝗹 𝗢𝗳𝗳𝗶𝗰𝗲 𝗭𝗲𝗿𝗼‑𝗗𝗮𝘆 + 𝗞𝗤𝗟 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻 CVE‑2026‑21509 is a high‑severity Microsoft Office zero‑day vulnerability actively exploited in the wild. Attackers can achieve arbitrary code execution through malicious documents embedding the legacy Shell.Explorer.1 OLE object, bypassing standard security prompts. The flaw affects Office 2016 through 365 (including LTSC builds), with emergency patches and registry mitigations now available. Defenders should prioritize applying updates or registry workarounds, while infrastructure teams patch corporate environments. To aid detection, the following KQL query highlights suspicious Office child processes spawned when opening documents weaponized with specially crafted OLE objects executing scripts.🫡 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 #Cybersecurity #MicrosoftOffice #ZeroDay #OLEVulnerability

    Post summary

    The post highlights a high‑severity, actively exploited Office zero‑day (CVE‑2026‑21509), details its technical aspects, and urges immediate patching and registry mitigations while offering a detection KQL query.

    339021311816.3K
    6.0K followersView on X
  • Haifei Li@HaifeiLi
    Disclosure

    Whoa! Who did this?? This seems to be the CVE-2026-21509 0day to me.. https://pub.expmon.com/analysis/311631/

    Post summary

    A user notes CVE-2026-21509 as a potential zero‑day, but provides no supporting details or evidence.

    326017413232.9K
    8.3K followersView on X
  • Zscaler ThreatLabz@Threatlabz
    Active Exploitation

    Zscaler ThreatLabz has uncovered a new APT28 campaign that exploits CVE-2026-21509. Tracked as Operation Neusploit, this activity targets countries in Central and Eastern Europe, and uses weaponized Microsoft RTF files to deliver two new backdoors that we have named MiniDoor and PixyNetLoader. Read the full technical analysis here: https://www.zscaler.com/blogs/security-research/apt28-leverages-cve-2026-21509-operation-neusploit

    Post summary

    The post reports a newly discovered APT28 campaign actively exploiting CVE‑2026‑21509 with weaponized RTF files to deploy backdoors, but lacks detailed technical or patch information.

    35621778318.6K
    8.2K followersView on X
  • John Hammond@_JohnHammond
    Patch

    Quick dance with CVE-2026-21509, a "Security Feature Bypass Vulnerability" and an emergency out-of-band fix from January Patch Tuesday (and an obligatory exaggerated YouTube thumbnail -- I apologize and appreciate folks who understand algorithm nuance) http://youtu.be/Ck8IPInn74A https://t.co/R9fcDphoqZ

    Post summary

    The post references CVE‑2026‑21509 as a security feature bypass vulnerability and announces an emergency out‑of‑band fix released on January Patch Tuesday.

    53001647432.0K
    311.4K followersView on X
  • Hackmanac@H4ckmanac
    Patch

    ‼️Microsoft Office Zero-Day (CVE-2026-21509) - Emergency Patch Issued for Active Exploitation Microsoft has issued an out-of-band emergency patch for a high-severity Microsoft Office zero-day, CVE-2026-21509 (CVSS 7.8), which is being actively exploited. The flaw is a security feature bypass that allows attackers to evade OLE protections by tricking users into opening a specially crafted Office file. The Preview Pane is not affected. Source: https://thehackernews.com/2026/01/microsoft-issues-emergency-patch-for.html

    Post summary

    Microsoft Office zero‑day CVE-2026-21509 is actively exploited; an emergency patch has been released and the vulnerability involves a security feature bypass with CVSS 7.8.

    26021733221.1K
    119.9K followersView on X
  • Steven Lim@0x534c
    Active Exploitation

    🔥𝗡𝗲𝘄 𝗔𝗣𝗧𝟮𝟴 𝗱𝗼𝗺𝗮𝗶𝗻 𝘂𝘀𝗲𝗱 𝗳𝗼𝗿 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟮𝟭𝟱𝟬𝟵 𝗰𝗮𝗺𝗽𝗮𝗶𝗴𝗻 Based on @anyrun_app sandbox submissions and intelligence lookup, I just found another new domain associated with APT28 used for CVE-2026-21509 attack campaign. The domain 48d83469-d0c6-4ade-8f82-e383fff094b8[.]webhook[.]site Let's Encrypt certificate was just created yesterday on the 7 Feb and hosted on a Hetzner Cloud Server residing in Germany. I am sharing the SHA256 of the word RTF document so that defenders can block or monitor this hash in their environment. 🫡 𝗔𝗣𝗧𝟮𝟴 𝗡𝗲𝘄 𝗗𝗼𝗺𝗮𝗶𝗻: 48d83469-d0c6-4ade-8f82-e383fff094b8[.]webhook[.]site 𝗪𝗼𝗿𝗱 𝗥𝗧𝗙 𝗦𝗛𝗔𝟮𝟱𝟲: 506e7512c897514e9d312a1532d2e2949ec8ebd73f6ca52740fb5e3306f08843 #Cybersecurity #Threathunting #APT28

    Post summary

    The post reports a new domain tied to an APT28 campaign exploiting CVE‑2026‑21509 and shares a hash of the malicious RTF payload for defenders, but offers no PoC, exploit code, patch, or technical vulnerability details.

    24001288113.6K
    6.0K followersView on X
  • Philippe Lagadec@decalage2
    General

    How can we detect malicious documents exploiting the recent 0-day in MS Office CVE-2026-21509? I designed a YARA rule for this, which detects all the malicious files that have been reported. https://decalage.info/CVE-2026-21509/ https://t.co/IJLmINjWMZ

    Post summary

    A user cites the newly discovered CVE-2026-21509 and notes a YARA rule that detects malicious documents, but provides no exploit code, active usage evidence, patch information, or technical vulnerability details.

    14201267910.3K
    5.3K followersView on X
  • 780th Military Intelligence Brigade (Cyber)@780thC
    Active Exploitation

    Russian state-sponsored threat group APT28 (aka Fancy Bear or UAC-0001) has launched a sophisticated espionage campaign targeting European military and government entities... Trellix https://www.trellix.com/blogs/research/apt28-stealthy-campaign-leveraging-cve-2026-21509-cloud-c2/ @Trellix

    Post summary

    APT28 is reportedly exploiting CVE‑2026‑21509 in a stealthy campaign targeting European military and government entities.

    05131114812.8K
    34.4K followersView on X
  • blackorbird@blackorbird
    General

    APT28: Geofencing as a Targeting Signal (CVE-2026-21509 Campaign) https://blog.synapticsystems.de/apt28-geofencing-as-a-targeting-signal-cve-2026-21509/ https://t.co/K719kejTdk

    Post summary

    The text references CVE-2026-21509 in relation to APT28 but does not provide technical details, exploitation evidence, or mitigation information.

    23501063812.5K
    39.9K followersView on X
  • Moonbeom(Daniel)@krNeoTra
    Patch

    Patch Diffing CVE-2026-21509 : Microsoft Office OLE Security Bypass https://blog.78researchlab.com/34cdb461-3e5b-808d-a9c9-dc1338adaccc

    Post summary

    The blog post focuses on a patch diff for CVE‑2026‑21509, outlining a Microsoft Office OLE security bypass and the corresponding fix.

    031193458.2K
    1.0K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ APT28 is targeting Ukraine and allied supply chains using a confirmed zero-day (CVE-2026-21513) and PRISMEX malware. It also exploits CVE-2026-21509, with LNK delivery possibly chaining both flaws to enable theft and file-wiping. 🔗 Read here → https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html

    Post summary

    APT28 is actively exploiting CVE‑2026‑21513 and CVE‑2026‑21509 against Ukrainian targets, chaining delivery via LNK files to steal data and wipe files; no PoC, patch, or technical details beyond the CVE IDs are provided.

    14541011913.6K
    1.6M followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    UPDATE: APT28 began exploiting the Office 1-day CVE-2026-21509 within 24 hours of disclosure, per Trellix. Targets now include European military and transport orgs, with phishing lures delivering multi-stage loaders and custom implants via cloud-hosted C2. 🔗 Infection chain, sectors hit, evasion design → https://thehackernews.com/2026/02/apt28-uses-microsoft-office-cve-2026.html#update

    Post summary

    APT28 has actively exploited CVE-2026-21509 within a day of its disclosure, targeting European military and transport organizations with phishing lures that deliver multi‑stage loaders and custom implants via cloud‑hosted C2, highlighting rapid exploitation and tailored malware delivery.

    5313872810.9K
    1.0M followersView on X
  • Szabolcs Schmidt@smica83
    Exploit

    'previewme.doc' looks like some kind of RedTeam exercise by @buffaloverflow CVE-2026-21509 exploit. https://bazaar.abuse.ch/sample/f0d443055143cbd6bce8ef96b52d430e2db321b37b8b93a2a9d0354651702790/ https://t.co/w72jQ0OVsc

    Post summary

    The tweet announces that a CVE‑2026‑21509 exploit sample is available, implying an exploit tool or PoC exists, but no further technical or mitigation details are provided.

    111086477.4K
    3.1K followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    #APT28 + CVE-2026-21509 = Operation Neusploit https://www.zscaler.com/blogs/security-research/apt28-leverages-cve-2026-21509-operation-neusploit MiniDoor is a lightweight 64-bit DLL written in C++. The registry keys set by the MiniDoor DLL dropper to steal email from Microsoft Outlook. PixyNetLoader analysis The dropper DLL used in variant 2 of the attack chain is new and previously undocumented.

    Post summary

    APT28 is actively exploiting CVE‑2026‑21509 in Operation Neusploit, using a custom MiniDoor DLL dropper to harvest Outlook emails.

    1191553521.8K
    39.9K followersView on X
  • Philippe Lagadec@decalage2
    General

    About the recent 0day vulnerability in MS Office (CVE-2026-21509): Samples or exploits have not been published yet, so it is not easy to develop detections. However we can try to guess how malicious documents might look like. (1/n)

    Post summary

    The post notes that no PoC or exploit samples are available for CVE-2026-21509 and provides no technical details, patch information, or exploitation evidence.

    218060309.5K
    5.3K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🛡️ Russia-linked APT28 exploited a newly disclosed Microsoft Office flaw within days of disclosure. CVE-2026-21509 was used via malicious RTF files, with geo-fenced delivery targeting Ukraine, Slovakia, and Romania. 🔗 Read → https://thehackernews.com/2026/02/apt28-uses-microsoft-office-cve-2026.html

    Post summary

    APT28 deployed malicious RTF files exploiting CVE‑2026‑21509 against Ukrainian, Slovakian, and Romanian targets shortly after the flaw was disclosed.

    82706498.7K
    1.0M followersView on X
  • Clandestine@akaclandestine
    Patch

    GitHub - suuhm/CVE-2026-21509-handler: PowerShell script to check, apply, and test the Kill-Bit protection for the CVE-2026-21509 Microsoft Office zero-day vulnerability affecting Office 2016/2019/LTSC. https://github.com/suuhm/CVE-2026-21509-handler

    Post summary

    A GitHub repository hosts a PowerShell script that applies and tests Kill‑Bit protection as a workaround for the CVE‑2026‑21509 Microsoft Office zero‑day affecting Office 2016/2019/LTSC.

    217051333.5K
    55.7K followersView on X
  • Steven Lim@0x534c
    Active Exploitation

    CVE-2026-21509 Observation Based on the detailed writeup on "APT28 geofencing as a targeting signal cve-2026-21509" by Synaptics System. Link: https://blog.synapticsystems.de/apt28-geofencing-as-a-targeting-signal-cve-2026-21509/ It takes only about 4 days for APT28 to weaponize CVE-2026-21509 as the first sample of the file hash first appeared on Jan 30. The intriguing part is the exploit surface of CVE-2026-21509 only becomes visible after the OLE reconstruction step. The article demonstrate how APT28 abuse Microsoft Office OLE vulnerability which causes Office to make incorrect trust decisions during document parsing and making the decision to access a remote shortcut via WebDAV for further code execution. A high level KQL detection construct for defenders to monitor your Office applications reaching out for external WebDAV activity: DeviceNetworkEvents | where Timestamp > ago(1h) | where InitiatingProcessCommandLine has "file://" | where InitiatingProcessVersionInfoProductName == "Microsoft Office" | where RemoteIPType == "Public" Defenders should add this two domains to their tenant block list as a defense against CVE-2026-21509 exploits: wellnessmedcare[.]org freefoodaid[.]com #Cybersecurity #OLEVulnerability #MSOffice

    Post summary

    APT28 has weaponized CVE-2026-21509, exploiting a Microsoft Office OLE flaw that enables remote code execution via WebDAV; the post offers detection guidance and domain-blocking mitigation steps.

    112149345.7K
    6.0K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftoffice2016-x64
Appmicrosoftoffice2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86

Explore more