Microsoft has released an out-of-band security update to fix an actively exploited Microsoft Office vulnerability tracked as CVE-2026-21509. The flaw allows attackers to bypass Office security protections via malicious documents and has been added to CISA's Known Exploited Vulnerabilities catalog.