Microsoft has issued three out-of-band updates in January 2026, a rare break from its usual Patch Tuesday schedule due to pressing threats. The most critical is CVE-2026-21509, a Microsoft Office vulnerability being actively exploited. Organisations should accelerate testing and deployment of these patches, prioritising protection of critical systems without skipping validation. Notify end users to minimise workflow disruptions and review Office macro permissions. Firms handling sensitive data or in high-profile sectors must act with urgency, as attackers target delays in patch deployment. These unexpected releases signal an increasingly dynamic threat landscape—remain vigilant with patching and cautious with email, even internal communications.
Related Articles
128: AWS Lambda Introduces Tenant Isolation Mode: Enhanced Security for Multi-Tenant Workloads
- News Summariser
- November 19, 2025
- 0
AWS Lambda has launched Tenant Isolation Mode, a significant upgrade for managing multi-tenant serverless workloads. Previously, achieving strict customer isolation required building complex, costly infrastructure […]
128: Record-Breaking Azure DDoS Attack: Lessons for Cloud Infrastructure and MSPs
- News Summariser
- November 17, 2025
- 0
Microsoft Azure recently withstood a record-breaking Distributed Denial-of-Service (DDoS) attack, reaching 15.72 terabits per second and involving over 500,000 unique IP addresses. This unprecedented scale […]
128: Google to Invest $1 Billion in New UK Data Centre
- News Summariser
- January 18, 2024
- 0
Google has revealed plans to invest $1 billion in constructing a new data center in Waltham Cross, Hertfordshire, underlining its dedication to bolstering the UK’s […]

