
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26107 is a use-after-free vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects Microsoft Excel 2016, Office 2019, Office 2021, Office 2024, Office LTSC 2021 and 2024, Microsoft 365 Apps for Enterprise (x86/x64), Office Online Server, and Office for macOS 2021 and 2024. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Microsoft Excel's memory management routines when processing spreadsheet files. A use-after-free condition arises when Excel accesses memory that has already been freed, enabling an attacker to control program execution flow. Exploitation requires local access and user interaction — specifically, a victim must open a maliciously crafted spreadsheet file — but requires no elevated privileges. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Microsoft MSRC, ZDI Blog).
Successful exploitation grants an attacker arbitrary code execution on the affected system with the privileges of the logged-in user, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive documents, modify or destroy data, install malware, or use the compromised system as a foothold for lateral movement within a network. The broad scope of affected products — spanning consumer and enterprise Office suites across Windows and macOS — significantly widens the potential attack surface (Microsoft MSRC).
EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) shortly after a spreadsheet file is opened.%TEMP%, %APPDATA%, or startup folders by the Excel process; newly created scripts or executables in user-writable directories.EXCEL.EXE to external IP addresses or domains not associated with Microsoft services; DNS queries for unusual domains initiated by Office processes.EXCEL.EXE; security logs showing process creation events with EXCEL.EXE as the parent process for unexpected child processes.HKCU\Software\Microsoft\Windows\CurrentVersion\Run) created around the time of file opening.Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday. Specific version targets include: Office Online Server updated to 16.0.10417.20102 or later; Excel 2016 updated to 16.0.5543.1000 or later; Office LTSC for Mac 2021/2024 updated to 16.107.26030819 or later; and Office 2019, LTSC 2021/2024, and Microsoft 365 Apps for Enterprise updated per guidance at https://aka.ms/OfficeSecurityReleases. As interim mitigations, organizations should educate users to avoid opening spreadsheet files from untrusted sources, consider implementing application whitelisting, and disable Office macros where not required (Microsoft MSRC, Rapid7 Blog).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets. Zero Day Initiative noted it in their monthly security update review, and Rapid7 included it in their Patch Tuesday analysis. Sophos also covered the March Patch Tuesday, noting the breadth of affected product families. Community sentiment treated this as a standard monthly patch priority — notable but not alarming given the absence of active exploitation or a public PoC (ZDI Blog, Rapid7 Blog, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."