Microsoft has released an emergency fix for a Microsoft Office vulnerability, tracked as CVE-2026-21509, and the US cybersecurity agency CISA has already added it to its list of flaws being exploited in real attacks. For most people using Office 2021 or later, the fix is almost effortless: close every Office app and open it again. Owners of Office 2016 and 2019 have a bit more to do.
What happened
The flaw was published on 26 January 2026. The National Vulnerability Database (NVD) describes it this way: “Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.” It carries a CVSS score of 7.8, rated High.
Put simply, Office has protections that are supposed to stop a dangerous document from doing harm, and this bug lets a malicious file slip past one of them. According to The Hacker News, citing Microsoft, an attacker has to convince the victim to open a specially prepared Office file. Microsoft also says the Preview Pane is not an attack vector, so merely seeing a file in the preview window does not trigger it.
On the same day, CISA added CVE-2026-21509 to its Known Exploited Vulnerabilities catalog, its list of flaws known to be exploited in the wild. US federal agencies were given until 16 February 2026 to deal with it. When a bug lands in that catalog on the day it is published, I take that as a sign to patch immediately rather than wait for the regular monthly cycle.
Who is affected
According to NVD, the flaw affects:
- Office 2016
- Office 2019
- Office LTSC 2021
- Office LTSC 2024
- Microsoft 365 Apps for Enterprise
How you get protected depends on your version. The Hacker News reports, citing Microsoft, that Office 2021 and later are covered by a service-side change, meaning Microsoft applied the fix on its end. The catch is that it only takes effect after you restart your Office apps. If you leave Word or Outlook open for weeks, as many of us do, you are not protected yet.
Office 2016 and 2019 need an actual update to a specific build number, listed in the table below.
In practice, this touches almost everyone. Office is on nearly every office PC and on plenty of home computers, and malicious documents sent by email remain one of the most common ways into small businesses.
By the numbers
| Item | Detail | Source |
|---|---|---|
| CVE | CVE-2026-21509 | NVD |
| Severity | CVSS 7.8 (High) | NVD |
| Published | 26 January 2026 | NVD |
| Added to CISA KEV | 26 January 2026 | NVD |
| CISA deadline for US agencies | 16 February 2026 | NVD |
| Office 2021 and later | Service-side fix, restart Office apps | The Hacker News, citing Microsoft |
| Office 2016 fixed build | 16.0.5539.1001 | The Hacker News, citing Microsoft |
| Office 2019 fixed build | 16.0.10417.20095 | The Hacker News, citing Microsoft |
| Preview Pane an attack vector | No | The Hacker News, citing Microsoft |
What to do now
These steps come from Microsoft and CISA guidance.
- Close all Office apps, including Outlook, Word, Excel and PowerPoint, then reopen them. This activates the service-side fix on Office 2021 and later.
- If you use Office 2016 or 2019, install the January 2026 security update now. Afterwards, check that your build is at least 16.0.5539.1001 (2016) or 16.0.10417.20095 (2019).
- Do not open unexpected Office attachments, even from contacts you know. A familiar name on an email does not prove the file is safe.
- If your organisation cannot patch right away, IT administrators should apply the temporary registry-based mitigation that Microsoft documents in its advisory, and then patch as soon as possible.
A tip for small teams: send one short message to everyone today asking them to fully close and reopen Office. It takes a minute and covers most of your machines.
Why it matters
This is not the most severe score we have seen, and it does require the victim to open a file. But that is exactly how many real attacks against small businesses start: an email that looks like an invoice, a CV or a contract, with a document attached. A flaw that weakens Office’s own safety checks makes that trick more effective.
The encouraging part is how simple the fix is for newer versions. The discouraging part is that a service-side fix only helps people who restart. My suggestion: treat “close and reopen Office” as part of your security routine, not just something to do when the app freezes.
Sources
- Microsoft Security Response Center, security update guide entry for CVE-2026-21509, January 2026, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
- NIST National Vulnerability Database, entry for CVE-2026-21509, 26 January 2026, https://nvd.nist.gov/vuln/detail/CVE-2026-21509
- The Hacker News, report on Microsoft’s emergency patch for the Office flaw, January 2026, https://thehackernews.com/2026/01/microsoft-issues-emergency-patch-for.html