Microsoft Office Zero-Day Exploited as Emergency Patch Counters Active Attacks
Microsoft has issued an emergency out-of-band security update to address a high-severity zero-day vulnerability in Microsoft Office that is already being actively exploited in the wild. The flaw, tracked as CVE-2026-21509, represents a significant escalation in the ongoing arms race between attackers and defenders, particularly as productivity software remains one of the most abused entry points for enterprise compromise. With a CVSS score of 7.8, the vulnerability is classified as high risk and affects multiple versions of Microsoft Office. Its real-world exploitation, confirmed by Microsoft and later acknowledged by U.S. federal cybersecurity authorities, underscores how rapidly threat actors are weaponizing … Read more