Microsoft rushes an emergency fix for an Office flaw already used in attacks

Reading Time: 5 min
18
techkahwa.net | 27 January 2026

Microsoft has released an emergency fix for a Microsoft Office vulnerability, tracked as CVE-2026-21509, and the US cybersecurity agency CISA has already added it to its list of flaws being exploited in real attacks. For most people using Office 2021 or later, the fix is almost effortless: close every Office app and open it again. Owners of Office 2016 and 2019 have a bit more to do.

What happened

The flaw was published on 26 January 2026. The National Vulnerability Database (NVD) describes it this way: “Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.” It carries a CVSS score of 7.8, rated High.

Put simply, Office has protections that are supposed to stop a dangerous document from doing harm, and this bug lets a malicious file slip past one of them. According to The Hacker News, citing Microsoft, an attacker has to convince the victim to open a specially prepared Office file. Microsoft also says the Preview Pane is not an attack vector, so merely seeing a file in the preview window does not trigger it.

On the same day, CISA added CVE-2026-21509 to its Known Exploited Vulnerabilities catalog, its list of flaws known to be exploited in the wild. US federal agencies were given until 16 February 2026 to deal with it. When a bug lands in that catalog on the day it is published, I take that as a sign to patch immediately rather than wait for the regular monthly cycle.

Who is affected

According to NVD, the flaw affects:

  • Office 2016
  • Office 2019
  • Office LTSC 2021
  • Office LTSC 2024
  • Microsoft 365 Apps for Enterprise

How you get protected depends on your version. The Hacker News reports, citing Microsoft, that Office 2021 and later are covered by a service-side change, meaning Microsoft applied the fix on its end. The catch is that it only takes effect after you restart your Office apps. If you leave Word or Outlook open for weeks, as many of us do, you are not protected yet.

Office 2016 and 2019 need an actual update to a specific build number, listed in the table below.

In practice, this touches almost everyone. Office is on nearly every office PC and on plenty of home computers, and malicious documents sent by email remain one of the most common ways into small businesses.

By the numbers

Item Detail Source
CVE CVE-2026-21509 NVD
Severity CVSS 7.8 (High) NVD
Published 26 January 2026 NVD
Added to CISA KEV 26 January 2026 NVD
CISA deadline for US agencies 16 February 2026 NVD
Office 2021 and later Service-side fix, restart Office apps The Hacker News, citing Microsoft
Office 2016 fixed build 16.0.5539.1001 The Hacker News, citing Microsoft
Office 2019 fixed build 16.0.10417.20095 The Hacker News, citing Microsoft
Preview Pane an attack vector No The Hacker News, citing Microsoft

What to do now

These steps come from Microsoft and CISA guidance.

  1. Close all Office apps, including Outlook, Word, Excel and PowerPoint, then reopen them. This activates the service-side fix on Office 2021 and later.
  2. If you use Office 2016 or 2019, install the January 2026 security update now. Afterwards, check that your build is at least 16.0.5539.1001 (2016) or 16.0.10417.20095 (2019).
  3. Do not open unexpected Office attachments, even from contacts you know. A familiar name on an email does not prove the file is safe.
  4. If your organisation cannot patch right away, IT administrators should apply the temporary registry-based mitigation that Microsoft documents in its advisory, and then patch as soon as possible.

A tip for small teams: send one short message to everyone today asking them to fully close and reopen Office. It takes a minute and covers most of your machines.

Why it matters

This is not the most severe score we have seen, and it does require the victim to open a file. But that is exactly how many real attacks against small businesses start: an email that looks like an invoice, a CV or a contract, with a document attached. A flaw that weakens Office’s own safety checks makes that trick more effective.

The encouraging part is how simple the fix is for newer versions. The discouraging part is that a service-side fix only helps people who restart. My suggestion: treat “close and reopen Office” as part of your security routine, not just something to do when the app freezes.

Sources

  • Microsoft Security Response Center, security update guide entry for CVE-2026-21509, January 2026, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
  • NIST National Vulnerability Database, entry for CVE-2026-21509, 26 January 2026, https://nvd.nist.gov/vuln/detail/CVE-2026-21509
  • The Hacker News, report on Microsoft’s emergency patch for the Office flaw, January 2026, https://thehackernews.com/2026/01/microsoft-issues-emergency-patch-for.html