
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26109 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized local attacker to execute arbitrary code. It was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday security update cycle. Affected products include Microsoft Excel 2016 (x86/x64), Microsoft Office 2019, Office 2021, Office 2024, Office LTSC 2021 and 2024 (Windows and macOS), Office Online Server (versions before 16.0.10417.20102), and Microsoft 365 Apps for Enterprise. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The root cause is an out-of-bounds read (CWE-125) in Microsoft Office Excel's file parsing logic, mapped to CAPEC-540 (Overread Buffers). An attacker can exploit this vulnerability by crafting a malicious Excel file that, when opened locally by a victim, triggers the out-of-bounds read condition and enables arbitrary code execution. The attack vector is local (AV:L), requires low privileges (PR:L), and no user interaction beyond opening the file, making it a file-based social engineering attack. No public proof-of-concept code has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation allows an attacker to execute arbitrary code with the same privileges as the user running Excel, resulting in high confidentiality, integrity, and availability impact on the affected system. This affects a broad range of Microsoft Office deployments across Windows (x86/x64) and macOS platforms, including enterprise environments using Microsoft 365 Apps. If the targeted user has elevated privileges, the impact could extend to broader system compromise and potential lateral movement within a network (Feedly, Microsoft MSRC).
.xlsx/.xls files received via email or downloaded from untrusted sources; new executable files or scripts created in user-writable directories (e.g., %APPDATA%, %TEMP%) shortly after Excel is opened.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); Excel process making unexpected outbound network connections.EXCEL.EXE; PowerShell or command execution logs triggered in the context of the Office process.Microsoft released security updates on March 10, 2026 addressing this vulnerability across all affected products. Specific fixed versions include: Microsoft Excel 2016 updated to build 16.0.5543.1000 or later, Office Online Server updated to 16.0.10417.20102 or later, Microsoft Office LTSC for Mac 2021 updated to 16.107.26030819 or later, and Microsoft Office LTSC for Mac 2024 updated to 16.107.26030819 or later. Users of Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, and Office 2024 should apply updates via the standard Microsoft Update mechanism. As a workaround, organizations should implement security awareness training to discourage users from opening Excel files from untrusted sources, and consider enabling Protected View for files received from the internet (Microsoft MSRC, Feedly).
CVE-2026-26109 was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Talos Intelligence, Sophos, Zero Day Initiative, and Tenable, though it was not highlighted as a top-priority vulnerability given the absence of active exploitation (Rapid7, Talos, Sophos). The Zero Day Initiative included it in their March 2026 security update review (ZDI). Community sentiment treated this as a standard patch-and-move-on vulnerability, with no significant controversy or researcher deep-dives published.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."