Microsoft Urgently Fixes Critical Office Flaw Under Active Exploitation
Microsoft patched CVE-2026-21509, a zero-day Office vulnerability actively exploited by attackers to bypass OLE security protections and execute malicious code through weaponized documents. The January 2026 Patch Tuesday addressed over 110 flaws total, with CISA flagging this critical threat for immediate attention. Office 2021+ users gain automatic protection after restarting, whereas 2016/2019 versions require manual registry tweaks. Attackers are delivering malicious files via email—your inbox remains the prime battleground. The full scope of affected products and step-by-step mitigation strategies reveal just how exposed legacy Office installations truly are.
Microsoft has patched a critical zero-day vulnerability in Office that attackers were already exploiting in the wild, as part of a massive January 2026 Patch Tuesday addressing over 110 security flaws.
Microsoft’s January 2026 Patch Tuesday tackles critical Office zero-day vulnerability already exploited by attackers, alongside more than 110 additional security flaws.
The most concerning issue, tracked as CVE-2026-21509, represents a security feature bypass that allows unauthorised attackers to circumvent OLE security protections in Microsoft 365 and Office. In simpler terms, hackers have discovered a way to bypass the safeguards Microsoft implemented to prevent malicious files from causing damage.
CISA wasted no time adding this vulnerability to its Known Exploited Vulnerabilities catalog, meaning federal agencies face strict remediation deadlines.
But that’s not where the bad news ends. CVE-2026-20805, affecting the Desktop Window Manager, has also seen active exploitation in the wild. This information disclosure vulnerability could leak sensitive data directly into attackers’ hands.
Three zero-days in total dominated this month’s security update—a reminder that even widely used software remains a favourite playground for threat actors.
The January 2026 Patch Tuesday cycle addressed between 112 and 115 security vulnerabilities across Microsoft’s product ecosystem. Eight earned the critical severity label, while 104 to 106 were classified as important. The security update also addressed vulnerabilities in SQL Server and Azure, extending protections beyond desktop applications.
Among the significant threats were multiple remote code execution flaws in Microsoft Office and Excel, including CVE-2026-20952 and CVE-2026-20953, both arising from use-after-free problems. CVE-2026-20952 carries a CVSS score of 8.4—definitely not something to ignore during your morning coffee.
Microsoft Word didn’t escape unscathed either. CVE-2026-20944, a remote code execution vulnerability caused by an out-of-bounds read flaw, could allow attackers to execute arbitrary code by convincing users to open specially crafted documents.
Excel faced similar issues with integer underflow flaws and untrusted pointer dereference problems, one scoring 7.8 on the CVSS scale.
The attack vector remains frustratingly familiar: malicious Office files delivered via email. Users who preview or open these specially crafted documents inadvertently hand over the keys to their systems. Yes, really—your inbox remains one of the most dangerous places on the internet. Fortunately, the Office Preview Pane is not an attack vector for this particular vulnerability.
Mitigation strategies vary by Office version. Users running Office 2021 or later benefit from automatic protection through a service-side fix after restarting their applications.
However, those still using Office 2016 or 2019 face manual registry modifications—adding certain COM Compatibility registry keys with Compatibility Flags DWORD values. Microsoft recommends backing up your registry before making these changes, as one wrong move can turn Tuesday into a very long week.
Affected products span Microsoft Office 2016, 2019, LTSC 2021, LTSC 2024, and Microsoft 365 Apps for Enterprise. SharePoint, Azure Core shared client library for Python, and Office Online Server also require security updates.
The takeaway? Apply these patches immediately. Attackers aren’t waiting, and neither should you.
Final Thoughts
Microsoft’s quick action to address a critical Office vulnerability serves as a stark reminder of the ongoing risks faced by users. With the flaw already being exploited before the patch was released, it’s crucial to prioritize updates without delay. This incident underscores the importance of maintaining security in the productivity software that supports countless businesses.
The Computer Techs Team is here to assist you in ensuring your systems are up-to-date and secure. Don’t wait for the next critical flaw to put your digital workspace at risk. Click on our contact us page to get in touch and let us help you stay protected.