PT-2026-7400 · Microsoft · Office Word

Msrc

+1

·

Published

2026-02-10

·

Updated

2026-03-10

·

CVE-2026-21514

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Word versions prior to February 2026 Patch Tuesday
Description A critical security flaw in Microsoft Word allows an attacker to bypass security features locally by exploiting reliance on untrusted inputs during security decisions. This issue, categorized as CWE-807, specifically bypasses Object Linking and Embedding (OLE) mitigations, potentially enabling malicious COM/OLE controls to execute. The vulnerability is actively exploited in the wild, and successful exploitation requires a victim to open a specially crafted document. The flaw impacts global and enterprise users of Microsoft Office. The vulnerability abuses trust decisions in OLE activation, potentially involving issues with how Word resolves embedded CLSIDs and validates OLE stream metadata within the Compound File Binary.
Recommendations Apply the February 2026 Patch Tuesday updates to all affected systems.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-01699
CVE-2026-21514

Affected Products

Office Word