Office Zero-Day Actively Exploited — Patch Now, MFA Enforced, NTLM Sunset Begins
An actively exploited Office zero-day (CVE-2026-21509) requires immediate patching across Office 2016–M365 Apps. MFA is now fully enforced for all M365 admin center sign-ins — no exceptions. And Microsoft published its NTLM deprecation timeline.
Read Full Edition →