
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26112 is an untrusted pointer dereference vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. It was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday security update. Affected products include Microsoft Excel 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise, Office Online Server (prior to 16.0.10417.20102), and Office LTSC versions (2021/2024) on both Windows and macOS platforms. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory).
The vulnerability is classified as CWE-822 (Untrusted Pointer Dereference), meaning Excel fails to properly validate pointer values derived from untrusted input before dereferencing them during file parsing. An attacker exploits this by crafting a malicious Excel file that, when opened by a victim, triggers the dereference of an attacker-controlled pointer, leading to arbitrary code execution in the context of the current user. The attack vector is local (the file must be opened by the user), requires no privileges, and requires user interaction — specifically, a user opening a malicious Excel document. No public proof-of-concept code has been identified (MSRC Advisory, ZDI Blog).
Successful exploitation results in complete compromise of the affected system's confidentiality, integrity, and availability, as arbitrary code executes in the context of the logged-in user. An attacker who achieves code execution could access sensitive data, install malware, modify files, or use the compromised system as a pivot point for lateral movement within a network. The broad scope of affected products — spanning Windows (x86/x64) and macOS, across consumer and enterprise Office editions — significantly widens the potential attack surface (MSRC Advisory).
%TEMP%, %APPDATA%) or startup folders shortly after an Excel file is opened; suspicious Excel files received via email or downloaded from external sources.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe, curl.exe); Excel process making unexpected outbound network connections.EXCEL.EXE to unknown or suspicious external IP addresses or domains; DNS queries for unusual domains initiated by the Office process.EXCEL.EXE as the parent process for command-line utilities; application crash logs or Dr. Watson entries related to Excel around the time of file opening.Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday update. Specific fixed versions include: Office Online Server updated to 16.0.10417.20102 or later; Excel 2016 updated to 16.0.5543.1000 or later; Office LTSC for Mac 2021/2024 updated to 16.107.26030819 or later. For Microsoft 365 Apps for Enterprise and Office LTSC 2021/2024 on Windows, refer to https://aka.ms/OfficeSecurityReleases for the applicable update. As interim mitigations, organizations should educate users not to open Excel files from untrusted sources, consider enabling Protected View for files from the internet, and apply application whitelisting to restrict unauthorized process spawning from Office applications (MSRC Advisory, Rapid7 Blog).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security vendors and researchers. The Zero Day Initiative noted it in their monthly security update review, and Rapid7 included it in their Patch Tuesday analysis (ZDI Blog, Rapid7 Blog). Sophos and other vendors highlighted the March 2026 update as addressing 15 product families, with Excel vulnerabilities among the notable fixes (Sophos Blog). Community sentiment focused on the importance of prompt patching given the broad product scope, though the lack of active exploitation tempered urgency.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."