Actively exploited Microsoft Office Zero‑Day (CVE‑2026‑21509)
Microsoft has issued an out of band emergency patch addressing an actively exploited Microsoft Office zero day vulnerability, tracked as CVE202621509. The flaw is a security feature bypass that allows attackers to circumvent core COM/OLE-based mitigations in Microsoft 365 and Microsoft Office.