CVE-2026-26109
vulnerability analysis and mitigation

Overview

CVE-2026-26109 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized local attacker to execute arbitrary code. It was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday security update cycle. Affected products include Microsoft Excel 2016 (x86/x64), Microsoft Office 2019, Office 2021, Office 2024, Office LTSC 2021 and 2024 (Windows and macOS), Office Online Server (versions before 16.0.10417.20102), and Microsoft 365 Apps for Enterprise. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).

Technical details

The root cause is an out-of-bounds read (CWE-125) in Microsoft Office Excel's file parsing logic, mapped to CAPEC-540 (Overread Buffers). An attacker can exploit this vulnerability by crafting a malicious Excel file that, when opened locally by a victim, triggers the out-of-bounds read condition and enables arbitrary code execution. The attack vector is local (AV:L), requires low privileges (PR:L), and no user interaction beyond opening the file, making it a file-based social engineering attack. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the same privileges as the user running Excel, resulting in high confidentiality, integrity, and availability impact on the affected system. This affects a broad range of Microsoft Office deployments across Windows (x86/x64) and macOS platforms, including enterprise environments using Microsoft 365 Apps. If the targeted user has elevated privileges, the impact could extend to broader system compromise and potential lateral movement within a network (Feedly, Microsoft MSRC).

Exploitation steps

  1. Craft a malicious Excel file: An attacker creates a specially crafted Excel file (.xlsx, .xls, or similar) that triggers the out-of-bounds read condition in the vulnerable Excel parsing code.
  2. Deliver the file to the target: The attacker distributes the malicious file via phishing email, malicious download link, shared network drive, or other social engineering methods to a user running a vulnerable version of Microsoft Excel.
  3. Victim opens the file: The target user opens the malicious Excel file using an unpatched version of Microsoft Excel on Windows or macOS.
  4. Trigger out-of-bounds read: Excel's file parsing logic reads beyond the allocated buffer boundary, corrupting memory in a controlled manner.
  5. Achieve code execution: The memory corruption is leveraged to redirect execution flow, resulting in arbitrary code execution with the privileges of the logged-in user (Feedly, Microsoft MSRC).

Indicators of compromise

  • File System: Unexpected or suspicious .xlsx/.xls files received via email or downloaded from untrusted sources; new executable files or scripts created in user-writable directories (e.g., %APPDATA%, %TEMP%) shortly after Excel is opened.
  • Process: Unusual child processes spawned by EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected outbound network connections.
  • Network: Outbound connections from the Excel process or its child processes to unknown or suspicious external IP addresses or domains.
  • Logs: Windows Event Logs showing application crashes or faulting module entries related to EXCEL.EXE; PowerShell or command execution logs triggered in the context of the Office process.

Mitigation and workarounds

Microsoft released security updates on March 10, 2026 addressing this vulnerability across all affected products. Specific fixed versions include: Microsoft Excel 2016 updated to build 16.0.5543.1000 or later, Office Online Server updated to 16.0.10417.20102 or later, Microsoft Office LTSC for Mac 2021 updated to 16.107.26030819 or later, and Microsoft Office LTSC for Mac 2024 updated to 16.107.26030819 or later. Users of Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, and Office 2024 should apply updates via the standard Microsoft Update mechanism. As a workaround, organizations should implement security awareness training to discourage users from opening Excel files from untrusted sources, and consider enabling Protected View for files received from the internet (Microsoft MSRC, Feedly).

Community reactions

CVE-2026-26109 was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Talos Intelligence, Sophos, Zero Day Initiative, and Tenable, though it was not highlighted as a top-priority vulnerability given the absence of active exploitation (Rapid7, Talos, Sophos). The Zero Day Initiative included it in their March 2026 security update review (ZDI). Community sentiment treated this as a standard patch-and-move-on vulnerability, with no significant controversy or researcher deep-dives published.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management