SB2026021053 - Security feature bypass vulnerability in Microsoft Word
Published: February 10, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Reliance on Untrusted Inputs in a Security Decision (CVE-ID: CVE-2026-21514)
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient mitigations for COM/OLE controls. A remote attacker can trick the victim into opening a specially crafted Word file, bypass implemented OLE mitigations and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install update from vendor's website.