OLE/COM security bypass — CVE-2026-21509

CVE_2026_21509

← All detection heuristics · CVE

critical CVE related CVE_2026_21509

What it means

Document contains Shell.Explorer.1 CLSID evidence plus OLE activation context.

Why it fires

CVE-2026-21509 is a Microsoft Office security feature bypass (CVSS 7.8) that exploits reliance on untrusted inputs in OLE/COM security decisions. Attackers craft documents with manipulated metadata so the parser incorrectly marks dangerous objects as 'Safe for Initialization,' allowing code execution without security warnings. Actively exploited in the wild. The scanner matches the Shell.Explorer.1 CLSID or ProgID and, for text forms, requires embedding context such as Ole10Native, RTF objdata, or an embedded PE marker; bare text is not enough.

Other CVE heuristics

CVE_2026_34621_RELATED CVE_2023_26369 CVE_2026_34621 CVE_2010_1297_FLASH_RICHMEDIA CVE_2010_1297_SWF_TRIGGER CVE_2011_0611_SWF_TRIGGER CVE_2009_1862_FLASH_RICHMEDIA CVE_2010_2883 CVE_2018_4901 CVE_2009_3459 CVE_2018_4990_JPX_EMBEDDED_CMD CVE_2018_4990_JPX_CMAP_TRIGGER CVE_2010_1240 CVE_2010_0188 CVE_2014_0514 CVE_2013_3346 CVE_2013_0640 CVE_2010_3654_FLASH_RICHMEDIA CVE_2007_5020_MAILTO_MSHTA CVE_2014_0496 CVE_2008_2551 CVE_2021_40444 CVE_2006_4694 CVE_2008_0118