CVE-2026-21509, a security feature bypass vulnerability in Microsoft Office, was weaponised as a zero-day in January 2026 by the Russian state-sponsored threat group APT28, also known as Fancy Bear, in a series of document-based attacks targeting Central and Eastern Europe including Ukraine and European Union member states. The vulnerability was one of 25 CVEs disclosed in 2026 that VulnCheck determined had been routinely targeted by adversaries by May of this year. CISA has recorded a 59 percent increase in new Known Exploited Vulnerabilities (KEVs) in 2026 compared to the same period in 2025. This article covers CVE-2026-21509 in detail, situates it within the broader 2026 exploit landscape, and documents the follow-on vulnerability CVE-2026-32202 added to the CISA KEV catalog in April 2026 after confirmation of active exploitation by APT28. Organisations running unpatched versions of Microsoft Office and Windows should treat this as an active threat requiring immediate remediation.
Key Facts
| Field | Detail |
| CVE | CVE-2026-21509 (primary); CVE-2026-21513 (chained); CVE-2026-32202 (follow-on) |
| Vulnerability Type | Security feature bypass (CVE-2026-21509); MSHTML flaw (CVE-2026-21513); Protection mechanism failure (CVE-2026-32202) |
| CVSS Score | CVE-2026-32202: 4.3; CVE-2026-21509 and CVE-2026-21513: scores not confirmed in available sources |
| Affected Products | Microsoft Office; Microsoft Windows; Windows Shell |
| Threat Actor | APT28 / Fancy Bear (Russian state-sponsored, attributed by VulnCheck and confirmed by Akamai/The Hacker News) |
| First Exploited | January 2026 (CVE-2026-21509 and CVE-2026-21513 as zero-days in document attacks) |
| Regions Targeted | Ukraine, Central and Eastern Europe, EU member states |
| KEV Status | CVE-2026-32202 added to CISA KEV catalog April 29, 2026; CVE-2026-21509 and CVE-2026-21513 listed in Recorded Future February 2026 analysis |
| Patch Available | Yes. CVE-2026-32202 patched in April 2026; apply all outstanding Microsoft security updates immediately |
Table 1: Vulnerability fact sheet. Sources: VulnCheck (May 2026), The Hacker News (April 2026), Recorded Future (March 2026), CISA KEV Catalog.
What Happened: The Attack Chain
In January 2026, APT28 began exploiting CVE-2026-21509 alongside CVE-2026-21513, a flaw in the Windows MSHTML engine, in a series of attacks against targets in Ukraine and European Union member states. The attack vector was document-based: malicious Windows Shortcut files were used to deliver multi-stage payloads through CVE-2026-21513, while CVE-2026-21509’s security feature bypass was used to suppress protections that would otherwise have flagged or blocked the malicious content. According to VulnCheck’s May 2026 routinely targeted vulnerabilities report, CVE-2026-21509 qualifies as routinely targeted, meaning it has been observed in active exploitation by threat actors, documented in ransomware campaigns or nation-state operations, and has sufficient public exploit density to represent a sustained risk.
The follow-on vulnerability, CVE-2026-32202, was added to CISA’s Known Exploited Vulnerabilities catalog on April 29, 2026. According to The Hacker News’ reporting that day, Akamai identified CVE-2026-32202 as stemming from an incomplete patch for CVE-2026-21510, which was itself exploited as a zero-day alongside CVE-2026-21513 by APT28 in attacks targeting Ukraine and EU member states. Microsoft updated its advisory for CVE-2026-32202 on April 28, 2026, acknowledging active exploitation. CVE-2026-32202 is classified as a protection mechanism failure in Microsoft Windows Shell with a CVSS score of 4.3 and was patched in April 2026.
Separately, a supply chain attack attributed to Lotus Blossom, a suspected Chinese state-sponsored threat actor, exploited CVE-2025-15556 in Notepad++ to replace legitimate update packages with malicious installers delivering Cobalt Strike Beacon and the Chrysalis backdoor. This attack affected users of Notepad++ versions prior to 8.8.9 and ran for six months before discovery. CISA added this to the KEV catalog on February 12, 2026. The Notepad++ incident and the APT28 Office exploitation share a structural element: both targeted software update and trust mechanisms rather than direct remote code execution.
The Broader 2026 Exploit Landscape
CVE-2026-21509 did not emerge in isolation. VulnCheck’s May 2026 report identified 25 CVEs disclosed in 2026 that have been routinely targeted by adversaries. CISA recorded a 59 percent increase in new KEVs compared to the same period in 2025. The Kaspersky Securelist Q1 2026 vulnerability landscape report notes that the registration of vulnerabilities is steadily gaining momentum, driven by the widespread use of AI tools to identify security flaws, a trend expected to accelerate exploit-driven attacks further.
Recorded Future’s February 2026 CVE landscape analysis identified 13 critical vulnerabilities requiring immediate remediation that month, down 43 percent from January’s 23, but all carrying a Very Critical risk score. Six of the 13 affected Microsoft products. A separate authentication bypass in Cisco Catalyst SD-WAN infrastructure, identified as CVE-2026-1731, was exploited by a threat actor tracked as UAT-8616, which chained it with an older vulnerability to achieve root-level access on Cisco SD-WAN systems. CISA issued Emergency Directive 26-03 requiring federal civilian agencies to remediate immediately.
June 2026’s Patch Tuesday from Microsoft addressed 200 vulnerabilities, with several categories showing atypical volumes. Microsoft issued patches for 360 browser vulnerabilities in the month, an order of magnitude higher than any prior month, attributing part of the increase to AI-assisted vulnerability discovery tools being applied at scale. A new class of denial-of-service vulnerability affecting HTTP/2 and HTTP/3 implementations, including CVE-2026-49975 known as HTTP/2 Bomb, also emerged in June, discovered in part by OpenAI’s Codex.
What This Means for Security Teams
The APT28 exploitation of CVE-2026-21509 and the related chain of vulnerabilities carries three operational implications for security teams in Europe, the UAE, and the US.
First, patch velocity matters more than patch comprehensiveness. The CVE-2026-32202 addition to the CISA KEV catalog in April was the direct result of an incomplete patch issued for an earlier vulnerability. Organisations that patched CVE-2026-21510 but did not apply the subsequent correction remained exposed. Tracking patch completeness against related CVE chains, not just individual CVEs, is the practice that would have caught this gap.
Second, document-based attacks exploiting trust mechanisms remain the most operationally reliable initial access vector for nation-state actors. The January 2026 APT28 campaign and the six-month Notepad++ supply chain attack both exploited the trust employees place in expected file types and software update processes. Technical controls at the file and process level are necessary but not sufficient without an employee population that treats unexpected documents and update prompts with scepticism.
Third, the CISA KEV catalog is now the minimum baseline for remediation prioritisation, not a ceiling. A 59 percent increase in new KEVs year over year means organisations that are only remediating KEVs are already behind. VulnCheck’s routinely targeted list includes vulnerabilities with confirmed adversary interest before they reach KEV status. Building remediation workflows that incorporate multiple threat intelligence sources rather than a single catalog is the practice the 2026 exploit landscape requires.
Immediate Actions
- Apply all outstanding Microsoft security updates including the April 2026 patch for CVE-2026-32202. Verify patch status specifically against the chain: CVE-2026-21510, CVE-2026-21509, CVE-2026-21513, and CVE-2026-32202.
- Update Notepad++ to version 8.8.9 or later immediately on all endpoints. Verify that the WinGUp update component is receiving cryptographically verified updates.
- Apply patches for Cisco Catalyst SD-WAN infrastructure against CVE-2026-1731 and CVE-2022-20775, particularly for externally accessible deployments. Check SSH authorized_keys files for unauthorised entries.
- Review Microsoft June 2026 Patch Tuesday guidance and apply browser patches. HTTP/2 server implementations including Microsoft IIS should be assessed against CVE-2026-49975.
- Subscribe to CISA KEV catalog updates and cross-reference against VulnCheck’s routinely targeted vulnerabilities list for early warning of adversary-confirmed exploitation.

Leave a Reply