boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-21509HIGH
Microsoft Office Security Feature Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .7215   99.4   YES
AFFECTED
  Product                            Versions  Fixed
  Microsoft 365 Apps for Enterprise  16.0.1 –  —
  Microsoft Office 2016              16.0.0 –  —
  Microsoft Office 2019              19.0.0 –  —
  Microsoft Office LTSC 2021         16.0.1 –  —
  Microsoft Office LTSC 2024         16.0.0 –  —
TIMELINE
  Dec 30  Reserved by microsoft
  Jan 26  Added to CISA KEV, remediation due 2026-02-16
  Jan 26  Published (CNA: microsoft)
CWE-807 · CNA: microsoft · CVSS v3.1 · 4 references · KEV due February 16, 2026

Description

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
December 30, 2025ReservedReserved by microsoft
January 26, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-02-16
January 26, 2026PublishedPublished (CNA: microsoft)

Affected

Affected products and packages — 5 rows
VendorProduct / PackageEcosystemVersion introducedFixed
MicrosoftMicrosoft 365 Apps for Enterprise16.0.1
MicrosoftMicrosoft Office 201616.0.0
MicrosoftMicrosoft Office 201919.0.0
MicrosoftMicrosoft Office LTSC 202116.0.1
MicrosoftMicrosoft Office LTSC 202416.0.0

Weaknesses

CWE-807

References (4)

Related

Authoritative record: CVE-2026-21509 at cve.org

Vendors: microsoft

Weaknesses: CWE-807

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-21509 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.