Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Microsoft Office Word Security Feature Bypass Vulnerability

Vulnerability

A security feature bypass vulnerability has been identified in Microsoft Office Word. This vulnerability arises from a reliance on untrusted inputs in security decisions, allowing an unauthorized attacker to locally bypass certain security features. The issue affects multiple versions of Microsoft Office, including the 2021 and 2024 LTSC releases for both Mac and Windows, as well as Microsoft 365 Apps for Enterprise.

Impact

Exploitation of this vulnerability allows for a local bypass of security features in Microsoft Office Word, specifically OLE mitigations that protect users from vulnerable COM/OLE controls.

Remediation

Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Instructions for downloading the update can be found in the Microsoft Office LTSC 2024 and 2021 release notes, as well as the Microsoft 365 Apps for Enterprise security update guidance.

Added: Feb 10, 2026, 6:32 PM
Updated: Feb 11, 2026, 1:51 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.9
remediation
0.0
relevance
2.7
threat
8.1
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.