Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    The cyberpunk classic that shaped modern sci-fi is finally coming to TV — everything we know

    March 15, 2026

    I tested the tiny Russell Hobbs coffee maker that uses grounds or Nespresso pods — but I discovered one infuriating drawback

    March 15, 2026

    Volunteers Find Oddly High Solar Flare Rates

    March 14, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Tech Gadgets»Worrying Microsoft Office security flaw patched – update now or risk hackers accessing your files
    Worrying Microsoft Office security flaw patched – update now or risk hackers accessing your files
    Tech Gadgets

    Worrying Microsoft Office security flaw patched – update now or risk hackers accessing your files

    The Tech GuyBy The Tech GuyJanuary 27, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement



    • Microsoft issues emergency patch for Office zero-day CVE-2026-21509
    • Vulnerability allows attackers to bypass OLE mitigations and execute malware
    • CISA adds flaw to KEV catalog; exploitation details remain undisclosed

    Microsoft has issued an emergency patch to fix a high-severity Office vulnerability that is being exploited in the wild as a zero-day.

    Advertisement

    The bug is described as a security bypass flaw: “Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally,” the National Vulnerability Database (NVD) explains.

    In other words, Office was making security decisions based on information it shouldn’t fully trust, and that was exploited by cybercriminals to execute malware, steal login credentials, and move laterally through the network.


    You may like

    How to patch and work around the bug

    It was said that the vulnerability is being actively exploited in the wild, and the US Cybersecurity and Infrastructure Security Agency (CISA) already added it to its Known Exploited Vulnerabilities (KEV) catalog.

    However, Microsoft did not say who the threat actors are, or who the victims were. We also don’t know what the scope of the campaign is, or if it already resulted in meaningful data theft, or possibly ransomware attacks.

    The bug is tracked as CVE-2026-21509 and was given a severity score of 7.8/10 (high).

    “This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office, which protect users from vulnerable COM/OLE controls,” Microsoft said in a security advisory.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Users running Office 2021 and later don’t have to do anything aside from restarting their Office applications, since the patch will be made server-side. Those running Office 2016 and 2019, will need to install these updates:

    Microsoft Office 2019 (32-bit edition) – 16.0.10417.20095

    Microsoft Office 2019 (64-bit edition) – 16.0.10417.20095


    You may like

    Microsoft Office 2016 (32-bit edition) – 16.0.5539.1001

    Microsoft Office 2016 (64-bit edition) – 16.0.5539.1001

    Those that cannot install the patches should make changes in Windows Registry, as mitigation. Microsoft has provided a step-by-step guide which can be found on this link.

    Via The Hacker News


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.



    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    I tested the tiny Russell Hobbs coffee maker that uses grounds or Nespresso pods — but I discovered one infuriating drawback

    March 15, 2026

    Huawei Enjoy 90 Pro Max and Enjoy 90 Plus get formally teased

    March 14, 2026

    Which phone-powered PC experience is better?

    March 14, 2026

    How to upgrade your car’s old audio system to work with Android Auto and Apple CarPlay

    March 14, 2026

    How to Make a Killing review: a serial killer story should not be this boring

    March 14, 2026

    iQOO Z11’s design revealed, pre-orders go live

    March 13, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20258 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    The cyberpunk classic that shaped modern sci-fi is finally coming to TV — everything we know

    March 15, 2026

    I tested the tiny Russell Hobbs coffee maker that uses grounds or Nespresso pods — but I discovered one infuriating drawback

    March 15, 2026

    Volunteers Find Oddly High Solar Flare Rates

    March 14, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.