FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word
2026-03-18T20:52:30Z•d4a717cd2cfec1701b77aef1faaa08282d986b1e0e07589b8c2148bd0f70610f
Attack Surface Reduction (ASR)CVE-2026-21514Iranian-linked actorsMark-of-the-WebMicrosoft WordOLE bypassOperation Epic FuryTenableattack surfaceemail gateway filteringexposure managementn-daypatchingvulnerability
What happened
CVE-2026-21514 is a Microsoft Word N-day that bypasses OLE and Mark‑of‑the‑Web protections, allowing embedded payloads to execute silently and evade user security prompts. Tenable’s exposure analysis found nearly 14 million affected assets across seven Tier‑1 countries (the vast majority in the U.S.), and advises urgent patching plus compensating controls (OLE/COM email gateway filtering, Attack Surface Reduction rules, and exposure‑management prioritization). The issue is highlighted in the context of Operation Epic Fury and concurrent Iranian‑nexus activity, underscoring large-scale exploita
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- d4a717cd2cfec1701b77aef1faaa08282d986b1e0e07589b8c2148bd0f70610f
- Enrichment time
- 2026-03-18T20:52:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.