Pharmaceutical

Technology News

  • Microsoft issues emergency out-of-band patch for Office zero-day CVE-2026-21509 exploited in attacks
    January 27, 2026, 2:28 PM EST. Microsoft issued an out-of-band security patch for a high-severity Office vulnerability tracked as CVE-2026-21509, described as a security feature bypass. The CVSS score is 7.8. Exploitation requires a user to open a specially crafted Office file, bypassing OLE mitigations in Microsoft 365 and Office. The company notes the Preview Pane is not an attack vector. For Office 2021 and later, protection is provided via a service-side change and users must restart Office apps. Office 2016 and 2019 users should install updates: Office 2019 32-bit/64-bit 16.0.10417.20095; Office 2016 32-bit/64-bit 16.0.5539.1001. As mitigation, Microsoft recommends a Windows Registry change (back up, then add a new key under COM Compatibility with a DWORD value 400). Microsoft credited MSTIC, MSRC, and the Office Product Group Security Team for the discovery.