Microsoft Patches CVE-2026-21509: Office Zero-Day Actively Exploited — What Security Teams Must Do Now
Microsoft has shipped an urgent fix for CVE-2026-21509, a Microsoft Office zero-day vulnerability that attackers are already using in the wild to bypass security features. The company’s advisory flags active exploitation while withholding technical specifics—often a sign that investigations and coordinated takedowns may still be underway. CISA has added CVE-2026-21509 to its Known Exploited Vulnerabilities…
