
Actively Exploited Microsoft Office Security Feature Bypass — PoC Public, CISA KEV Listed
CybersecurityVulnerabilitiesExploitsPhishing
A high-severity (CVSS 7.8) security feature bypass vulnerability in Microsoft Office is being actively exploited. The flaw stems from unvalidated input handling (CWE-807), allowing malicious OLE/COM objects in crafted documents to bypass protections. It affects Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps on x86/x64, with exploitation requiring only a user to open a phishing-delivered file. Microsoft released an out-of-band emergency patch on January 26, 2026, and confirmed targeting of government agencies, critical infrastructure, and maritime/transport sectors.