Cisco Talos Blog

Microsoft releases update to address zero-day vulnerability in Microsoft Office

Microsoft has published three out-of-band (OOB) updates so far in January 2026. One of these updates was released to address a vulnerability, CVE-2026-21509, affecting Microsoft Office that has been reportedly exploited in the wild.
favicon
blog.talosintelligence.com
blog.talosintelligence.com
Image for the article: Microsoft releases update to address zero-day vulnerability in Microsoft Office