Russian hackers are targeting a new zero-day Office 365, so patch now or face an attack



  • Russian APT28 (Fancy Bear) exploited CVE-2026-21509 in Microsoft Office days after patch release
  • Malicious DOC files sent to Ukrainian government agencies via themed phishing lures
  • CISA added the flaw to its KEV catalog, urging an immediate patch

Russian hackers attacked Ukrainian government agencies using a high-severity Microsoft Office vulnerability just days after a patch was released.

On January 26, 2026, Microsoft pushed an emergency fix to address CVE-2026-21509, an untrusted input dependency in a security decision vulnerability, which allows unauthorized attackers to bypass Microsoft Office security features locally. The bug was given a severity score of 7.6/10 (high) and was said to have already been abused in the wild as a day zero.



Leave a Comment

Your email address will not be published. Required fields are marked *