Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Vimeo Confirms User and Customer Data Breach

    April 29, 2026

    Sony’s Table-Tennis Robot Beat Elite Human Players With Unorthodox Moves

    April 29, 2026

    Apple’s testing 12-month subscriptions with monthly payments

    April 29, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Tech Gadgets»Worrying Microsoft Office security flaw patched – update now or risk hackers accessing your files
    Worrying Microsoft Office security flaw patched – update now or risk hackers accessing your files
    Tech Gadgets

    Worrying Microsoft Office security flaw patched – update now or risk hackers accessing your files

    The Tech GuyBy The Tech GuyJanuary 27, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement



    • Microsoft issues emergency patch for Office zero-day CVE-2026-21509
    • Vulnerability allows attackers to bypass OLE mitigations and execute malware
    • CISA adds flaw to KEV catalog; exploitation details remain undisclosed

    Microsoft has issued an emergency patch to fix a high-severity Office vulnerability that is being exploited in the wild as a zero-day.

    Advertisement

    The bug is described as a security bypass flaw: “Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally,” the National Vulnerability Database (NVD) explains.

    In other words, Office was making security decisions based on information it shouldn’t fully trust, and that was exploited by cybercriminals to execute malware, steal login credentials, and move laterally through the network.


    You may like

    How to patch and work around the bug

    It was said that the vulnerability is being actively exploited in the wild, and the US Cybersecurity and Infrastructure Security Agency (CISA) already added it to its Known Exploited Vulnerabilities (KEV) catalog.

    However, Microsoft did not say who the threat actors are, or who the victims were. We also don’t know what the scope of the campaign is, or if it already resulted in meaningful data theft, or possibly ransomware attacks.

    The bug is tracked as CVE-2026-21509 and was given a severity score of 7.8/10 (high).

    “This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office, which protect users from vulnerable COM/OLE controls,” Microsoft said in a security advisory.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Users running Office 2021 and later don’t have to do anything aside from restarting their Office applications, since the patch will be made server-side. Those running Office 2016 and 2019, will need to install these updates:

    Microsoft Office 2019 (32-bit edition) – 16.0.10417.20095

    Microsoft Office 2019 (64-bit edition) – 16.0.10417.20095


    You may like

    Microsoft Office 2016 (32-bit edition) – 16.0.5539.1001

    Microsoft Office 2016 (64-bit edition) – 16.0.5539.1001

    Those that cannot install the patches should make changes in Windows Registry, as mitigation. Microsoft has provided a step-by-step guide which can be found on this link.

    Via The Hacker News


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.



    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    ‘The connective tissue between your data, your people, and your goals’: Google Cloud positions Gemini Enterprise as the one-stop shop for all your agentic affairs

    April 28, 2026

    Xiaomi releases open-weight MiMo-V2.5 AI model, claims “frontier-level agentic capability”

    April 28, 2026

    Verizon’s new family deal costs $25 a line with unlimited data, but here’s the fine print

    April 28, 2026

    If you’ve got money to burn, I found a near-perfect laptop

    April 28, 2026

    NYT Strands hints and answers for Tuesday, April 28 (game #786)

    April 27, 2026

    Poco C81 Pro is here with a 6.9-inch display, 6,000mAh battery

    April 27, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20258 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Vimeo Confirms User and Customer Data Breach

    April 29, 2026

    Sony’s Table-Tennis Robot Beat Elite Human Players With Unorthodox Moves

    April 29, 2026

    Apple’s testing 12-month subscriptions with monthly payments

    April 29, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.