FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word

2026-03-18T20:52:30Zd4a717cd2cfec1701b77aef1faaa08282d986b1e0e07589b8c2148bd0f70610f
Attack Surface Reduction (ASR)CVE-2026-21514Iranian-linked actorsMark-of-the-WebMicrosoft WordOLE bypassOperation Epic FuryTenableattack surfaceemail gateway filteringexposure managementn-daypatchingvulnerability

What happened

CVE-2026-21514 is a Microsoft Word N-day that bypasses OLE and Mark‑of‑the‑Web protections, allowing embedded payloads to execute silently and evade user security prompts. Tenable’s exposure analysis found nearly 14 million affected assets across seven Tier‑1 countries (the vast majority in the U.S.), and advises urgent patching plus compensating controls (OLE/COM email gateway filtering, Attack Surface Reduction rules, and exposure‑management prioritization). The issue is highlighted in the context of Operation Epic Fury and concurrent Iranian‑nexus activity, underscoring large-scale exploita

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
d4a717cd2cfec1701b77aef1faaa08282d986b1e0e07589b8c2148bd0f70610f
Enrichment time
2026-03-18T20:52:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word · Baitaphish