CVE-2026-21509
KEVHIGH 7.8EPSS 72.6%
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS
- 72.55% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2026-01-26
- Published
- 2026-01-26
- Updated
- 2026-07-30
Proof-of-concept exploits (7)
- kimstars/Ashwesker-CVE-2026-2150911★ · 2026-01-27
- gavz/CVE-2026-21509-PoC20★ · 2026-01-28
- kaizensecurity/CVE-2026-215090★ · 2026-02-05
- DameDode/CVE-2026-21509-POC0★ · 2026-03-12
- razureink/cve-2026-21509-office_security_bypass_reproduction0★ · 2026-07-23
- IsMyPhonePwned/mimic4★ · 2026-02-05
- SimoesCTT/CTT-NFS-Vortex-RCE