Microsoft Security Updates – 27 January 2026

Microsoft has released a security update to fix a vulnerability across multiple versions of Microsoft Office.

The addressed vulnerability could allow the local attacker to bypass security restrictions to the affected system.

Microsoft Office Security Feature Bypass Vulnerability (CVE-2026-21509):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Bypass Security

Sample of the affected products:

  • Microsoft Office 2016 (64-bit edition).
  • Microsoft Office LTSC 2024 for 64-bit editions.
  • Microsoft 365 Apps for Enterprise for 64-bit Systems.
  • Microsoft Office 2019 for 64-bit editions.

It should be highlighted that Microsoft is aware that the zero-day vulnerability “CVE-2026-21509” is being exploited in the wild.

Vulnerabilities

CVE-2026-21509

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft MSRC

References