惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
博客园 - Franky
博客园 - 三生石上(FineUI控件)
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
人人都是产品经理
人人都是产品经理
博客园 - 【当耐特】
L
LangChain Blog
Stack Overflow Blog
Stack Overflow Blog
H
Help Net Security
爱范儿
爱范儿
罗磊的独立博客
博客园_首页
美团技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
V
Visual Studio Blog
T
Tailwind CSS Blog

Cyber Security Advisories - MS-ISAC

Multiple Vulnerabilities in Ivanti Products Could Allow for Arbitrary Code Execution A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution Critical Patches Issued for Microsoft Products, September 8, 2026 Multiple Vulnerabilities in DellSecure Connect Gateway Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in SonicWall SMA1000 Series Appliances Could Allow for Remote Code Execution Multiple Vulnerabilities in PaperCut Products Could Allow for Remote Code Execution Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution A Vulnerability in Zoom Clients Could Allow for Remote Code Execution Critical Patches Issued for Microsoft Products, August 11, 2026 Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code Execution A Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution Critical Patches Issued for Microsoft Products, July 14, 2026 Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution A Vulnerability in PAN-OS Could Allow for Authentication Bypass Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
A Vulnerability in Microsoft Office Could Allow for Secur...
2026-01-27 · via Cyber Security Advisories - MS-ISAC

MS-ISAC ADVISORY NUMBER:

2026-007

DATE(S) ISSUED:

01/27/2026

OVERVIEW:

A vulnerability has been discovered in Microsoft Office which could allow for a security feature bypass. Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer. You can create and edit documents containing text and images, work with data in spreadsheets and databases, and create presentations and posters. Successful exploitation of the flaw relies on an attacker sending a specially crafted Office file and convincing recipients to open it. It also noted that the Preview Pane is not an attack vector.

THREAT INTELLIGENCE:

Microsoft reports CVE-2026-21509 was exploited in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) also added CVE-2026-21509 to its Known Exploited Vulnerabilities (KEV) catalog.

SYSTEMS AFFECTED:

  • Microsoft Office 2019 (32-bit edition) prior to 16.0.10417.20095
  • Microsoft Office 2019 (64-bit edition) prior to 16.0.10417.20095
  • Microsoft Office 2016 (32-bit edition) prior to 16.0.5539.1001
  • Microsoft Office 2016 (64-bit edition) prior to 16.0.5539.1001

RISK:

Government:

Large and medium government entitiesHIGH

Small governmentMEDIUM

Businesses:

Large and medium business entitiesHIGH

Small business entitiesMEDIUM

TECHNICAL SUMMARY:

A vulnerability in Microsoft Office could allow for security feature bypass. Details of the vulnerability are as follows:

Tactic: Initial Access (TA0001):

Technique: User Execution (T1204):

  • Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. Microsoft has not shared any details about the nature and the scope of attacks exploiting CVE-2026-21509.​​​​​​

Successful exploitation of the flaw relies on an attacker sending a specially crafted Office file and convincing recipients to open it. It also noted that the Preview Pane is not an attack vector.

RECOMMENDATIONS:

We recommend the following actions be taken:

  • Apply appropriate updates provided by Microsoft or other vendors which use this software to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
  • Safeguard 7.1 : Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
  • Safeguard 7.2: Establish and Maintain a Remediation Process: Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.
  • Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
  • Safeguard 7.5 : Perform Automated Vulnerability Scans of Internal Enterprise Assets: Perform automated vulnerability scans of internal enterprise assets on a quarterly, or more frequent, basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool.
  • Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
  • Safeguard 12.1: Ensure Network Infrastructure is Up-to-Date: Ensure network infrastructure is kept up-to-date. Example implementations include running the latest stable release of software and/or using currently supported network-as-a-service (NaaS) offerings. Review software versions monthly, or more frequently, to verify software support.
  • Safeguard 18.1: Establish and Maintain a Penetration Testing Program: Establish and maintain a penetration testing program appropriate to the size, complexity, and maturity of the enterprise. Penetration testing program characteristics include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise controls; frequency; limitations, such as acceptable hours, and excluded attack types; point of contact information; remediation, such as how findings will be routed internally; and retrospective requirements.
  • Safeguard 18.2: Perform Periodic External Penetration Tests: Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conducted through a qualified party. The testing may be clear box or opaque box.
  • Safeguard 18.3: Remediate Penetration Test Findings: Remediate penetration test findings based on the enterprise’s policy for remediation scope and prioritization.
  •  Restrict use of certain websites, block downloads/attachments, block Javascript, restrict browser extensions, etc. (M1021: Restrict Web-Based Content)
  • Safeguard 2.3: Address Unauthorized Software: Ensure that unauthorized software is either removed from use on enterprise assets or receives a documented exception. Review monthly, or more frequently.
  • Safeguard 2.7: Allowlist Authorized Scripts: Use technical controls, such as digital signatures and version control, to ensure that only authorized scripts, such as specific .ps1, .py, etc., files, are allowed to execute. Block unauthorized scripts from executing. Reassess bi-annually, or more frequently.
  • Safeguard 9.3: Maintain and Enforce Network-Based URL Filters: Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise assets.
  • Safeguard 9.6: Block Unnecessary File Types: Block unnecessary file types attempting to enter the enterprise’s email gateway.
  • Use intrusion detection signatures to block traffic at network boundaries. (M1031: Network Intrusion Prevention)
  • Safeguard 13.3: Deploy a Network Intrusion Detection Solution: Deploy a network intrusion detection solution on enterprise assets, where appropriate. Example implementations include the use of a Network Intrusion Detection System (NIDS) or equivalent cloud service provider (CSP) service.
  • Safeguard 13.8: Deploy a Network Intrusion Prevention Solution: Deploy a network intrusion prevention solution, where appropriate. Example implementations include the use of a Network Intrusion Prevention System (NIPS) or equivalent CSP service.
  • Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050: Exploit Protection)
  • Safeguard 10.5: Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.

REFERENCES:

CISA
CVE
Microsoft