
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26108 is a heap-based buffer overflow vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute code locally. Disclosed on March 10, 2026, as part of Microsoft's Patch Tuesday release, it affects Excel 2016, Microsoft 365 Apps (Enterprise), Office 2019, 2021, and 2024 (Windows and macOS), Office Long-Term Servicing Channel 2021 and 2024, and Office Online Server (versions prior to 16.0.10417.20102). It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), with an associated attack pattern of CAPEC-92 (Forced Integer Overflow). Exploitation requires a local attack vector with no privileges required, but does require user interaction — specifically, a victim must open a specially crafted Excel file. When the malicious file is processed, Excel writes data beyond the bounds of an allocated heap buffer, enabling arbitrary code execution in the context of the current user (Microsoft MSRC, Feedly).
Successful exploitation results in remote code execution with high impact across confidentiality, integrity, and availability — an attacker can achieve complete compromise of the affected system. Because the vulnerability executes code in the context of the logged-in user, privilege escalation may be possible if the victim has administrative rights. Potential consequences include unauthorized data access, data theft, installation of malware or ransomware, and disruption of system availability (Microsoft MSRC).
.xlsx or .xls file designed to trigger a heap-based buffer overflow when parsed by Microsoft Excel's file processing routines..xlsx, .xls, .xlsm) received from external or unknown sources; newly created executable files or scripts in user temp directories (%TEMP%, %APPDATA%) following Excel file opens.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected outbound network connections.EXCEL.EXE to unknown or suspicious IP addresses or domains; DNS queries for unusual domains initiated shortly after opening an Excel file.EXCEL.EXE; security logs showing new process creation with EXCEL.EXE as parent process for command-line utilities.Microsoft released security updates on March 10, 2026 addressing this vulnerability across all affected products, including Excel 2016, Microsoft 365 Apps (Enterprise), Office 2019/2021/2024, Office Long-Term Servicing Channel 2021/2024, Office Online Server (patched to 16.0.10417.20102 or later), and Office macOS 2021/2024. Updates are available through Microsoft's standard update channels (Windows Update, Microsoft Update Catalog, and Microsoft AutoUpdate for macOS). As a temporary workaround until patching is complete, organizations should restrict users from opening Excel files from untrusted or external sources, and consider disabling macros and external content in Excel via Group Policy (Microsoft MSRC).
The vulnerability was covered as part of broader March 2026 Patch Tuesday reporting by multiple security outlets. Zero Day Initiative (ZDI) included it in their March 2026 security update review, and Rapid7 noted it in their Patch Tuesday analysis. Sophos, Tenable, Lansweeper, and other vendors published Patch Tuesday summaries referencing this CVE. Community coverage was routine, with no exceptional alarm given the lack of active exploitation or public PoC at time of disclosure (ZDI Blog, Rapid7 Blog, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."