
🚨 Microsoft Office Word 0-day Vulnerability Actively Exploited in the Wild Source: https://cybersecuritynews.com/microsoft-office-word-0-day-vulnerability/ A critical zero-day vulnerability in Microsoft Word, tracked as CVE-2026-21514, was disclosed on February 10, 2026, allowing attackers to bypass essential security protections. CVE-2026-21514 exploits a weakness in how Microsoft Word handles security decisions based on untrusted inputs, categorized as CWE-807. The vulnerability specifically bypasses Object Linking and Embedding (OLE) mitigations implemented by Microsoft to protect users from malicious COM/OLE controls. These OLE controls enable documents to embed and interact with external objects. However, improper validation allows attackers to circumvent protective measures. #cybersecuritynews #vulnerability
Post summary
CVE-2026-21514 is a critical zero‑day in Microsoft Word that bypasses OLE mitigations and is actively exploited in the wild, with no publicly disclosed patch or PoC provided.

















