CVE-2026-26112
vulnerability analysis and mitigation

Overview

CVE-2026-26112 is an untrusted pointer dereference vulnerability in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code locally. It was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday security update. Affected products include Microsoft Excel 2016, Office 2019, Office 2021, Office 2024, Microsoft 365 Apps for Enterprise, Office Online Server (prior to 16.0.10417.20102), and Office LTSC versions (2021/2024) on both Windows and macOS platforms. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory).

Technical details

The vulnerability is classified as CWE-822 (Untrusted Pointer Dereference), meaning Excel fails to properly validate pointer values derived from untrusted input before dereferencing them during file parsing. An attacker exploits this by crafting a malicious Excel file that, when opened by a victim, triggers the dereference of an attacker-controlled pointer, leading to arbitrary code execution in the context of the current user. The attack vector is local (the file must be opened by the user), requires no privileges, and requires user interaction — specifically, a user opening a malicious Excel document. No public proof-of-concept code has been identified (MSRC Advisory, ZDI Blog).

Impact

Successful exploitation results in complete compromise of the affected system's confidentiality, integrity, and availability, as arbitrary code executes in the context of the logged-in user. An attacker who achieves code execution could access sensitive data, install malware, modify files, or use the compromised system as a pivot point for lateral movement within a network. The broad scope of affected products — spanning Windows (x86/x64) and macOS, across consumer and enterprise Office editions — significantly widens the potential attack surface (MSRC Advisory).

Exploitation steps

  1. Craft malicious Excel file: An attacker creates a specially crafted Excel file (.xlsx, .xls, or similar) that contains malformed data structures designed to place an attacker-controlled value into a pointer field processed by Excel's file parsing logic.
  2. Deliver the file to the target: The attacker distributes the malicious file via phishing email, malicious download link, or shared network drive, targeting users running a vulnerable version of Microsoft Excel.
  3. Induce user to open the file: The attacker uses social engineering to convince the victim to open the file. No administrative privileges are required on the victim's system.
  4. Trigger untrusted pointer dereference: Upon opening, Excel processes the malformed file and dereferences the attacker-controlled pointer (CWE-822), causing execution to redirect to attacker-controlled memory or code.
  5. Achieve code execution: Arbitrary code executes in the security context of the current user, enabling the attacker to drop payloads, establish persistence, exfiltrate data, or move laterally within the network (MSRC Advisory).

Indicators of compromise

  • File System: Unexpected files (e.g., executables, scripts, DLLs) written to user temp directories (%TEMP%, %APPDATA%) or startup folders shortly after an Excel file is opened; suspicious Excel files received via email or downloaded from external sources.
  • Process: Unusual child processes spawned by EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe, curl.exe); Excel process making unexpected outbound network connections.
  • Network: Outbound connections from EXCEL.EXE to unknown or suspicious external IP addresses or domains; DNS queries for unusual domains initiated by the Office process.
  • Logs: Windows Event Logs showing process creation events (Event ID 4688) with EXCEL.EXE as the parent process for command-line utilities; application crash logs or Dr. Watson entries related to Excel around the time of file opening.

Mitigation and workarounds

Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday update. Specific fixed versions include: Office Online Server updated to 16.0.10417.20102 or later; Excel 2016 updated to 16.0.5543.1000 or later; Office LTSC for Mac 2021/2024 updated to 16.107.26030819 or later. For Microsoft 365 Apps for Enterprise and Office LTSC 2021/2024 on Windows, refer to https://aka.ms/OfficeSecurityReleases for the applicable update. As interim mitigations, organizations should educate users not to open Excel files from untrusted sources, consider enabling Protected View for files from the internet, and apply application whitelisting to restrict unauthorized process spawning from Office applications (MSRC Advisory, Rapid7 Blog).

Community reactions

The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security vendors and researchers. The Zero Day Initiative noted it in their monthly security update review, and Rapid7 included it in their Patch Tuesday analysis (ZDI Blog, Rapid7 Blog). Sophos and other vendors highlighted the March 2026 update as addressing 15 product families, with Excel vulnerabilities among the notable fixes (Sophos Blog). Community sentiment focused on the importance of prompt patching given the broad product scope, though the lack of active exploitation tempered urgency.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management