Sploitus

CVE-2026-21509

15 known exploits for CVE-2026-21509

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Affected products
Office
Microsoft 365 Apps
All versions
Microsoft Office
= 2016, 2019
Microsoft Office Long Term Servicing Channel
= 2021, 2024
CVSS 3.1
7.8 HIGH
EPSS
72.2% (99th percentile)
Weakness
CWE-807
NVD status
Analyzed
Published
2026-01-26
CVE-2026-21509 at NVD
Authoritative description, scoring and affected products

15 known exploits for CVE-2026-21509

Proof-of-concept code and exploit modules indexed by Sploitus