CVE-2026-21509
Known exploited · CISA KEV
CVSS 7.8 HIGH: reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a… EPSS 73% (99th percentile).
CISA federal remediation date Feb 16 · date passed