Microsoft’s early-2026 patch cycle drew heightened attention after the company issued an out-of-band security update for CVE-2026-21509, a Microsoft Office security feature bypass vulnerability, signaling elevated threat conditions and a need for rapid patch deployment. Threat-intelligence reporting emphasized that attacker interest often accelerates immediately after Patch Tuesday as defenders race to remediate, and it prioritized vulnerabilities most likely to be weaponized based on factors such as known exploitation, public disclosure, criticality, and Microsoft’s exploitability assessments.
Separate executive-focused coverage highlighted the broader operational challenge of CVE volume growth and the need for CISOs to triage “signal vs. noise” in vulnerability management, including attention to Patch Tuesday items described as actively exploited. However, one referenced CSO Online page is primarily an opinion piece on purple teaming and functions largely as a navigation hub to other stories rather than providing substantive details on the Office out-of-band vulnerability or a single, specific exploitation event.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
BeyondTrust released a fix for a critical remote code execution vulnerability affecting its remote access tools. The remediation was highlighted in February 2026 security news coverage.
Microsoft's February 2026 Patch Tuesday addressed six new vulnerabilities that were already being actively exploited. This was highlighted in contemporaneous coverage as a notable remediation event.
CERT-UA reported limited in-the-wild exploitation of CVE-2026-21509 in attacks using a malicious Office document, WebDAV retrieval, DLL and shellcode deployment, COM hijacking, a scheduled task, and COVENANT C2 via Filen. The activity was attributed to APT28.
On January 26, 2026, Microsoft released an out-of-band patch for CVE-2026-21509, a Microsoft Office security feature bypass vulnerability. The flaw stood out as the most significant issue associated with the January patch cycle.
Microsoft issued its January 2026 Patch Tuesday security updates, including fixes for vulnerabilities such as CVE-2026-20805 and multiple Office and Windows flaws. Reporting described the release as moderate in volume.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
flare.io
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.