CVE-2026-21511Disclosure(microsoft / 365_apps)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office
  • office_long_term_servicing_channel
  • sharepoint_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-11); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
365_appsofficeoffice_long_term_servicing_channelsharepoint_serverword

5 versions affected across 5 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-10: 1Mentions · 2026-02-11: 3Mentions · 2026-02-13: 1Mentions · 2026-02-25: 1Active Exploitation · 2026-02-11: 2Patch / Workaround · 2026-02-11: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-13: 102-1002-1102-1302-25
Signal classification3 categories
Disclosure
350.0%
Active Exploitation
233.3%
General
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-113
Active Exploitation2Disclosure1
2026-02-131
Disclosure1
2026-02-251
General1
Full discourse6 posts
  • CERT Azerbaijan@CERTAzerbaijan
    Disclosure

    “Microsoft Office” proqram təminatında uzaqdan kod icrası riski yaradan təhlükəsizlik boşluğu (CVE-2026-21511) aşkarlanıb. #ETX #MilliCERT #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/R1LliXTMNm

    Post summary

    A remote code execution vulnerability (CVE-2026-21511) was identified in Microsoft Office, with no PoC, exploit, or patch information provided in the tweet.

    0001188
    134 followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft (つづき) ・CVE-2026-21238 7.8 Windows Ancillary Function Driver for WinSock ・CVE-2026-21241 7  Windows Ancillary Function Driver for WinSock ・CVE-2026-21253 7  メールスロット ファイル システム ・CVE-2026-21511 7.5 Microsoft Office Outlook

    Post summary

    The post enumerates several newly disclosed CVEs with associated severity scores and affected Microsoft products, but does not provide exploitation details or mitigation steps.

    10000123
    89 followersView on X
  • Stamus Networks@StamusN
    General

    New CVEs: CVE-2026-21510 & CVE-2026-21511 Patching isn’t enough. Have you validated whether exploitation already occurred? Here’s how to hunt for indicators using Clear NDR: https://hubs.la/Q042Tg2x0 #NetworkSecurity #ThreatHunting #BlueTeam #NDR #CyberDefense https://t.co/rTP52UiPrQ

    Post summary

    The tweet announces two new CVEs and urges teams to verify if exploitation has already occurred, offering a link to a threat‑hunting tool for investigation.

    0000075
    1.1K followersView on X
  • Patel Mahendra@Mahendrak29
    Active Exploitation

    https://whatsapp.com/channel/0029VbAre6eKQuJNLsryuQ0u/111 🔥 Actively Exploited / Zero-Day CVEs Patched Today. - CVE-2026-21510 - CVE-2026-21513 - CVE-2026-21519 - CVE-2026-21533 - CVE-2026-21514 - CVE-2026-21525 - CVE-2026-21511 @cyber @Cyberdost @cybertruck

    Post summary

    The message declares that a set of CVE-2026-215xx zero‑day vulnerabilities are actively exploited and have been patched today.

    00000106
  • Patel Mahendra@Mahendrak29
    Active Exploitation

    •CVE-2026-21533 – Windows Remote Desktop Services Elevation of Privilege •CVE-2026-21514 – Microsoft Word Security Feature Bypass •CVE-2026-21525 – Windows Remote Access Connection Manager DoS (exploited in the wild) •CVE-2026-21511 – Microsoft Outlook Spoofing

    Post summary

    The excerpt lists multiple CVEs and notes that CVE‑2026‑21525 is being actively exploited in the wild.

    00000152
  • CVE@CVEnew
    Disclosure

    CVE-2026-21511 Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. https://www.cve.org/CVERecord?id=CVE-2026-21511

    Post summary

    The post announces CVE-2026-21511, a deserialization flaw in Microsoft Office Outlook that permits network spoofing; no PoC, exploit, or patch information is provided.

    00000166
    56.5K followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--
Appmicrosoftword2016-x64
Appmicrosoftword2016-x86

Explore more