Emergency Patch Issued for Microsoft Office, 365 Over Hacking Threat

Emergency Patch Issued for Microsoft Office, 365 Over Hacking Threat

Microsoft has released an emergency patch for a vulnerability in the company’s Office programs that’s already being exploited by hackers. 

On Monday, the company disclosed the flaw, CVE-2026-21509, which affects Microsoft 365 Apps for Enterprise and Microsoft Office 2019 and 2016, in addition to the Microsoft Office LTSC (Long-Term Service Channel) 2024 and Microsoft Office LTSC 2021.

Microsoft suggests the threat is being used in phishing attacks against vulnerable systems. That’s because successful exploitation requires local access to the PC, which could involve tricking the user into opening a malicious document.

“Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally,” adds a report from cybersecurity authority CVE.org. That feature is Object Linking and Embedding (OLE), which can integrate content, images, and links from different applications into one document. 

“This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office which protect users from vulnerable COM/OLE controls,” the company said without elaborating. Microsoft also warns that hackers have already been abusing the bug, including circulating computer code to exploit the attack. 

Recommended by Our Editors

The company’s patch is already rolling out. “Customers on Office 2021 and later will be automatically protected via a service-side change, but will be required to restart their Office applications for this to take effect,” the company says.

But in some bad news, Microsoft is still working to release a patch for Microsoft Office 2016 and 2019. Still, the company says customers on these versions can follow steps in its vulnerability report, including adding new registry keys to protect them from the threat. 



Newsletter Icon

Get Our Best Stories!

Stay Safe With the Latest Security News and Updates


SecurityWatch Newsletter Image

Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.

By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy
Policy.

Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

About Our Expert

Autor

  • Gaby Souza é criador do MdroidTech, especialista em tecnologia, aplicativos, jogos e tendências do mundo digital. Com anos de experiência testando dispositivos e softwares, compartilha análises, tutoriais e notícias para ajudar usuários a aproveitarem ao máximo seus aparelhos. Apaixonado por inovação, mantém o compromisso de entregar conteúdo original, confiável e fácil de entender