Cyber Posture

CVE-2026-21514

HighCISA KEVActive Exploitation

Published: 10 February 2026

Published
10 February 2026
Modified
11 February 2026
KEV Added
10 February 2026
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0448 89.2th percentile
Risk Priority 38 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-21514 is a high-severity Reliance on Untrusted Inputs in a Security Decision (CWE-807) vulnerability in Microsoft Office Long Term Servicing Channel. Its CVSS base score is 7.8 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Stealth (T1211); ranked in the top 10.8% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

The strongest mitigations our analysis identified are NIST 800-53 AC-24 (Access Control Decisions) and SI-10 (Information Input Validation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation for Stealth (T1211). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly mitigates CVE-2026-21514 by requiring timely installation of Microsoft patches as provided in MSRC guidance to remediate the flaw in Word's security decision-making.

prevent

Prevents exploitation of the vulnerability by enforcing validation of untrusted inputs prior to their use in security decisions within Microsoft Office Word, directly countering CWE-807.

prevent

Ensures access control decisions, such as those bypassed in Word, are made at trusted decision points isolated from untrusted inputs, preventing local security feature bypass.

MITRE ATT&CK Enterprise TechniquesAI

T1211 Exploitation for Stealth Stealth
Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.
Why these techniques?

The vulnerability explicitly enables bypassing a security feature in Microsoft Office Word via exploitation of untrusted inputs, directly mapping to T1211 (Exploitation for Defense Evasion).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

NVD Description

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

Deeper analysisAI

CVE-2026-21514 is a vulnerability in Microsoft Office Word caused by reliance on untrusted inputs in a security decision, corresponding to CWE-807. Published on 2026-02-10, it enables an unauthorized attacker to bypass a security feature locally. The issue carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating high severity due to substantial impacts on confidentiality, integrity, and availability.

Exploitation requires local access with low complexity and no privileges, but user interaction is necessary. An unauthorized attacker can leverage this to bypass security protections in Word, potentially leading to high-level compromise of the affected system given the elevated confidentiality, integrity, and availability impacts.

Microsoft's Security Response Center (MSRC) offers update guidance and mitigation details at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514. The vulnerability is also referenced in CISA's Known Exploited Vulnerabilities Catalog at https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21514.

Details

CWE(s)
KEV Date Added
10 February 2026

Affected Products

microsoft
365 apps
all versions
microsoft
office long term servicing channel
2021, 2024

CVEs Like This One

CVE-2026-21509Same product: Microsoft 365 Appsboth on KEV
CVE-2026-20944Same product: Microsoft 365 Apps
CVE-2025-21363Same product: Microsoft 365 Apps
CVE-2026-20949Same product: Microsoft 365 Apps
CVE-2026-20956Same product: Microsoft 365 Apps
CVE-2025-26629Same product: Microsoft 365 Apps
CVE-2025-24077Same product: Microsoft 365 Apps
CVE-2025-21365Same product: Microsoft 365 Apps
CVE-2025-21397Same product: Microsoft 365 Apps
CVE-2025-21364Same product: Microsoft 365 Apps

References