The images in this article were generated with artificial intelligence. How we publish
Microsoft has published this week off-schedule security updates to correct a high-gravity vulnerability in Microsoft Office that is already being exploited in attacks. The failure, recorded as CVE-2026-21509, affects several editions of Office, including Microsoft 365 Apps for Enterprise and the latest LTSC versions, and forces managers and users to act quickly alike. For the official description of vulnerability, see the Microsoft guide: MSRC - CVE-2026-21509, and for an independent summary of the vulnerability register the tab is available in the NVD: NVD - CVE-2026-21509.
The company defines the failure as a omission of a security measure in Office that allows a local attacker, not authenticated, to avoid protections designed to mitigate risks associated with vulnerable COM / OLE controls. In practice, the observed operating vector requires the attacker to convince the victim to open a malicious Office file; Microsoft points out that the preview panel is not the point of entry, but there have been low-complexity attacks that require user interaction.

Microsoft has already released emergency patches for several editions administered by its cloud service and for recent LTSC versions, but has recognized that No updates yet available for Office 2016 and Office 2019 and will work to publish them as soon as possible. Meanwhile, the company has proposed a mitigation measure based on the Windows Register that can reduce the possibility of exploitation in these environments, although official instructions are confusing for many administrators.
If you work with Office 2016 or 2019 and cannot apply an immediate patch, Microsoft recommends to close all Office applications and back up the Register before any modification - edit the Registry incorrectly can leave the system unstable -; Microsoft explains how to do it in your guide: How to back up and restore Windows Registry. The proposed mitigation is to create or verify the existence of a specific branch under the Common Office key, add the subkey called {EAB22AC3-30C1-11CF-A7EB-00C05BAE0B} within COM Compatibility and, in that subkey, create a DWORD value (32 bits) called Compatibility Flags with data 400. After saving the changes, the protection would come into effect by relaunching any Office application.
Repeat it in simple words: close all Office applications, back up the Register, open the Registry Editor (regedit), navigate to the route corresponding to your installation (the route varies if you have Office of 32 or 64 bits and if it is Click-to-Run), create the COM Compatibility key under Common if it does not exist, add the key to the indicated identifier and within it creates the DWORD Compatibility Flags with the value 400. If you are not comfortable making changes to the Register, you are responsible for waiting for the official patch or for technical assistance.

Microsoft has not published technical details about who discovered vulnerability or the precise way in which it is exploited in nature, and has limited information to prevent the multiplication of opportunistic attacks. This increases the importance of implementing updates as soon as they are available and of taking additional preventive measures: avoiding opening documents from unknown shipments, disabling macros when they are not necessary, and requiring security controls on mail and messaging channels that reach end-users.
The recent context is relevant: in the Patch Tuesday of January 2026 Microsoft remended more than 100 failures, including several days zero assets that were being exploited. In addition, in recent weeks the company has had to publish other patches outside the regular calendar to correct problems arising from these updates, which highlights the dynamic and critical of the current security landscape. To follow the security notes and updates, see the Microsoft update center: Microsoft Security Update Guide.
In short: if your organization uses Microsoft 365 Apps for Enterprise or the LTSC versions that already received the patch, apply the update as soon as possible. If you are dependent on Office 2016 or 2019, back up and, if you decide to apply mitigation through the Register, follow the steps carefully or delegate the task to IT personnel. Whatever your situation, act cautiously to unexpected files and expect additional instructions and patches from Microsoft.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...