The images in this article were generated with artificial intelligence. How we publish
Microsoft has confirmed an ongoing incident that prevents some users from opening files from Office for the web and Microsoft Teams, including applications such as Excel and PowerPoint in their online mode. The company has labelled the problem as a critical incident and, according to the statement published on its state channel, is investigating telemetry between services to identify the root of the failure. View the official notice at the administration center can help IT managers assess the scope: MO1329446.
This type of cuts repeats a pattern we have recently seen in Microsoft: cache configuration problems that affected MFA registration and configuration, backend change regressions that blocked Teams Free functions and errors introduced by browser updates. That record suggests that integration between service layers and continuous deployments remain vulnerable points on massive and multi-region platforms.

The implications go beyond the mere nuisance: when the cloud tools of productivity are inaccessible, operational continuity is resisted, delays are generated in regulated processes and the risk that users will resort to unapproved solutions - such as messaging services or personal storage - which increases exposure to data leakage and phishing. From a contractual perspective, organizations should quantify the impact against their Service Level Agreements and document operational losses.
To mitigate the immediate impact, affected companies and users should validate the service status in official sources such as the Microsoft 365 status account ( MSFT365Status) and the Office status panel ( status.office.com), and implement resilience measures already envisaged in their runbooks. Access local copies critical documents using OneDrive / SharePoint in non-connected mode or using desktop applications that synchronize files locally can offer an immediate output until the web service is restored.

In addition to temporary solutions, I recommend that the security and operations teams review internal policies: confirm that the versioner and backup of essential documents are active, strengthen warnings to supplanting communications that attempt to exploit the confusion of the incident, and audit any unusual access during and after the event to detect side movements or exfiltration.
At the strategic level, IT managers should require cloud suppliers to be clear in the deployment and reversion processes (rollback), require more stringent testing in representative production environments and maintain continuity plans that consider alternative routes for critical processes. For organizations with high dependency in one suite, assess redundancy or interoperability capabilities with secondary solutions may reduce risks of complete cessation in future incidents.
Finally, maintain proactive communication with users and customers: it explains what is affected, what steps have been taken and when they can expect a partial or total resolution. Transparency reduces repeated consultations to support and limits improvised actions that make the security position worse. To follow the state in real time and official updates, check the mentioned Microsoft sources and check the notices in the management center if you are a tenant administrator: MO1329446.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...