CVE-2026-26107
vulnerability analysis and mitigation

Overview

CVE-2026-26107 is a use-after-free vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects Microsoft Excel 2016, Office 2019, Office 2021, Office 2024, Office LTSC 2021 and 2024, Microsoft 365 Apps for Enterprise (x86/x64), Office Online Server, and Office for macOS 2021 and 2024. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Microsoft Excel's memory management routines when processing spreadsheet files. A use-after-free condition arises when Excel accesses memory that has already been freed, enabling an attacker to control program execution flow. Exploitation requires local access and user interaction — specifically, a victim must open a maliciously crafted spreadsheet file — but requires no elevated privileges. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Microsoft MSRC, ZDI Blog).

Impact

Successful exploitation grants an attacker arbitrary code execution on the affected system with the privileges of the logged-in user, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive documents, modify or destroy data, install malware, or use the compromised system as a foothold for lateral movement within a network. The broad scope of affected products — spanning consumer and enterprise Office suites across Windows and macOS — significantly widens the potential attack surface (Microsoft MSRC).

Exploitation steps

  1. Craft a malicious spreadsheet: An attacker creates a specially crafted Excel file (.xlsx, .xls, or similar) designed to trigger the use-after-free condition in Excel's memory management routines upon opening.
  2. Deliver the payload: The attacker distributes the malicious file via phishing email, malicious download link, or shared network drive, targeting users with vulnerable Office versions.
  3. Induce victim interaction: The victim opens the malicious spreadsheet using an unpatched version of Microsoft Excel. No macros or additional user actions beyond opening the file are necessarily required.
  4. Trigger the use-after-free: Excel processes the malformed file, causing a freed memory region to be accessed, which the attacker's payload leverages to redirect execution flow.
  5. Achieve code execution: Arbitrary code runs in the context of the victim's user account, enabling the attacker to install backdoors, exfiltrate data, or pivot to other systems on the network (Microsoft MSRC).

Indicators of compromise

  • Process: Unusual child processes spawned by EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) shortly after a spreadsheet file is opened.
  • File System: Unexpected files written to %TEMP%, %APPDATA%, or startup folders by the Excel process; newly created scripts or executables in user-writable directories.
  • Network: Outbound connections from EXCEL.EXE to external IP addresses or domains not associated with Microsoft services; DNS queries for unusual domains initiated by Office processes.
  • Logs: Windows Event Log entries (Event ID 1000/1001) indicating application crashes or faults in EXCEL.EXE; security logs showing process creation events with EXCEL.EXE as the parent process for unexpected child processes.
  • Registry: New or modified Run keys (HKCU\Software\Microsoft\Windows\CurrentVersion\Run) created around the time of file opening.

Mitigation and workarounds

Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday. Specific version targets include: Office Online Server updated to 16.0.10417.20102 or later; Excel 2016 updated to 16.0.5543.1000 or later; Office LTSC for Mac 2021/2024 updated to 16.107.26030819 or later; and Office 2019, LTSC 2021/2024, and Microsoft 365 Apps for Enterprise updated per guidance at https://aka.ms/OfficeSecurityReleases. As interim mitigations, organizations should educate users to avoid opening spreadsheet files from untrusted sources, consider implementing application whitelisting, and disable Office macros where not required (Microsoft MSRC, Rapid7 Blog).

Community reactions

The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets. Zero Day Initiative noted it in their monthly security update review, and Rapid7 included it in their Patch Tuesday analysis. Sophos also covered the March Patch Tuesday, noting the breadth of affected product families. Community sentiment treated this as a standard monthly patch priority — notable but not alarming given the absence of active exploitation or a public PoC (ZDI Blog, Rapid7 Blog, Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management