CVE-2026-26110
vulnerability analysis and mitigation

Overview

CVE-2026-26110 is a type confusion vulnerability (CWE-843) in Microsoft Office that allows an unauthorized local attacker to execute arbitrary code without requiring user interaction or elevated privileges. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects a broad range of Microsoft Office products including Office 2016, 2019, 2021, 2024, Office LTSC 2021/2024, Microsoft 365 Apps for Enterprise, and Office for Android. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) per NVD, while ENISA rates it 8.4 (High) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), meaning the application accesses a memory resource using a type that is incompatible with the type originally allocated, potentially allowing an attacker to manipulate program control flow or memory contents. The attack vector is local (AV:L), requires low privileges (PR:L per NVD), and no user interaction, making it exploitable by any local user on an affected system. A technical analysis published on Medium by researcher Kaloyan Stefanov provides additional details on the exploitation mechanics (Microsoft MSRC). For Office for Android, versions prior to 16.0.19822.20000 are vulnerable; for Office 2016, versions prior to 16.0.5543.1000 are affected.

Impact

Successful exploitation grants an attacker the ability to execute arbitrary code locally with high impact to confidentiality, integrity, and availability of the affected system. All three CIA triad components are rated HIGH, meaning an attacker could fully compromise the affected Office installation and potentially the underlying host. Given the breadth of affected products — spanning desktop, macOS, and Android platforms — the potential attack surface is significant across enterprise environments (Microsoft MSRC).

Mitigation and workarounds

Microsoft released security patches on March 10, 2026, addressing all affected products. Organizations should apply the following updates immediately:

  • Office for Android / Microsoft 365 Copilot (Android): Update to version 16.0.19822.20000 or later.
  • Microsoft Office 2016: Update to version 16.0.5543.1000 or later.
  • Office LTSC for Mac 2021/2024: Update to version 16.107.26030819 or later.
  • Microsoft 365 Apps for Enterprise, Office LTSC 2021/2024, Office 2019: Apply the latest updates via the Office Security Releases page.

Given the no-user-interaction requirement and high CVSS score, this should be treated as a high-priority patch in enterprise patch management programs (Microsoft MSRC).

Community reactions

The vulnerability received broad coverage as part of the March 2026 Patch Tuesday cycle, which addressed 83–84 CVEs in total. Security outlets including Tenable, Rapid7, Qualys, Krebs on Security, Bleeping Computer, and CSO Online highlighted CVE-2026-26110 among the notable Office vulnerabilities patched this cycle (Tenable Blog, Rapid7 Blog). A technical analysis was published on Medium by researcher Kaloyan Stefanov, and the vulnerability was discussed on Infosec.Exchange (Mastodon). PC Gamer and other mainstream tech outlets also covered the Office security flaws, reflecting the wide user base affected.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management