Microsoft issues emergency Office patch after attacks
Microsoft has released an out-of-band security update for a high-severity vulnerability in Microsoft Office that has been exploited in attacks. Details are scarce, but the flaw, CVE-2026-21509, allows a security feature to be bypassed if a victim opens a malicious document. Users running Office 2021 and later are automatically protected, while users of Office 2016 and 2019 must install the security update or apply the mitigations Microsoft describes.
What this means for your organisation
The older Office versions are the problem here, and they tend to live on machines outside the normal patching flow: production terminals, legacy caseworker clients and PCs at subcontractors. When Microsoft steps outside its regular update cycle, it signals that exploitation is already happening, and your prioritisation should reflect that.
Berigo recommends
- Identify where Office 2016 and 2019 are still in use, including devices outside central management.
- Roll out the update immediately, and apply Microsoft's mitigations where patching cannot happen at once.
- Put a plan in place to retire Office versions that are no longer protected by default.
- Remind staff how to handle attachments from unknown senders while the rollout is under way.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch