The images in this article were generated with artificial intelligence. How we publish
Microsoft is investigating a problem that prevents certain third-party applications from launching Microsoft Office or opening documents on Windows systems updated since June 9, 2026. The failure affects Word, Excel, PowerPoint, Access and other Office applications when they start from within applications using OLE Automation, and in some cases the document or application does not open and no error message appears, which complicates the detection of the failure.
Among the programs reported by users as affected are professional tools such as CCH Engagement, Zotero, Workpaper Manager and dental software such as Dentrix and Softdent; however, the exact scope remains in Microsoft research. The common denominator is the use of OLE / COM automation to control or open Office objects from external processes, a technique used for accounting solutions, file management and reference libraries.

From the technical point of view, OLE Automation involves calls between processes that depend on COM interfaces and execution permissions, so a change in how Windows records or authorizes those calls after an update can break the integration without affecting Office when it opens directly. So Microsoft recommends, as a temporary measure, open the applications or documents directly from Office rather than from the application that invokes them.
For end users the most immediate consequence is loss of productivity in workflows that integrate Office with specialized software; for organizations, there are also greater operational risks if these integrations are part of regulatory or customer delivery processes. A silent failure (without visible error) increases the likelihood that critical tasks will fail without being detected for example, ungenerated accounting reports or inaccessible clinical documents in consultation.
Immediate practical recommendations: First, if affected, use the temporary solution to open documents directly from Office or from the File Explorer. Second, report and coordinate with the application provider concerned to check whether there are already patches or specific instructions. Third, record evidence (screenshots, application logs, Windows Event Viewer events) to accelerate the diagnosis with support.
For IT equipment and security officers, avoid drastic actions such as uninstalling safety updates without assessing impact. In critical environments it may be appropriate to delay the massive implementation of recent updates to confirm the resolution, but always following corporate patch policies and maintaining essential protections. If you need an organization-wide solution, Microsoft indicates that business customers can contact Microsoft Support for Business to get a centralized workaround.
In addition, active and review telemetry and alerts related to automation and application failures: Windows event log, Office log and third-party application availability metrics will help you identify processes that do not complete file opening. Implement automated integration tests (smoke tests) in post-patch production environments can detect such regressions before they impact end users.
From a safety perspective, there is no public indication that this is an exploitable vulnerability by third parties; it seems rather a regression of compatibility. However, any change that breaks automated processes can open indirect vectors (e.g. users who, due to frustration, enable macro or resort to unsafe practices). Strengthen internal communications to ensure that employees follow safe procedures at the time of the occurrence.

Microsoft has said it works on a resolution that will arrive in a future Windows update; meanwhile it is appropriate to follow the official note and status updates published by the company. Microsoft's technical data sheet on the affected update and public notice are available on the Microsoft support portal: Windows update notice of June 9, 2026.
If you are a developer or maintain integrations using OLE / COM you should review Office automation documentation to understand what calls may be affected and prepare mitigation in the application layer (e.g. reattempts, pre-launch validations or alternative document opening routes). Microsoft's technical documentation on Office Automation can serve as a useful reference: Office Automation (Microsoft Docs).
In short, the best strategy for the coming days is the combination of temporary mitigation (open documents directly), communication with suppliers, active monitoring and coordination with Microsoft support if your organization requires it. Maintain contingency procedures for critical processes dependent on Office and prepare change management for when the final correction is published.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...