tag
Ole
CVE-2026-21509
misc
HIGH
KEV
EPSS 72%
Malicious DOCX/OLE CLSID Object Embedding Builder (CVE-2026-21509)
CVE-2026-21509 concerns Microsoft Word's handling of embedded OLE objects referencing attacker-chosen COM CLSIDs inside a .docx package. The included PoC is a pure-Python builder that assembles a syntactically valid OOXML .docx package containing a minimal…
Unverified
2026-07-05
CVE-2025-21298
binary
CRITICAL 9.8
EPSS 81%
Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)
CVE-2025-21298 is a critical Windows OLE memory-corruption vulnerability in ole32.dll that can be triggered through malicious RTF content. In Outlook scenarios, preview-pane rendering is sufficient to trigger the vulnerable parsing flow, making this…
Patched
2026-05-16