CVE-2026-26113
vulnerability analysis and mitigation

Overview

CVE-2026-26113 is an untrusted pointer dereference vulnerability in Microsoft Office that allows an unauthorized local attacker to execute arbitrary code. Disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday, it affects Microsoft Office 2016, 2019, 2021, 2024 (Windows and macOS), Microsoft 365 Apps for Enterprise, and SharePoint Server 2016, 2019, and Subscription Edition. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) per Microsoft's advisory, and 8.4 (High) per ENISA's scoring (Microsoft MSRC, Feedly).

Technical details

The vulnerability is classified as CWE-822 (Untrusted Pointer Dereference), meaning the application dereferences a pointer that is derived from untrusted input without adequate validation, potentially allowing an attacker to control the memory address being accessed. The attack vector is local (AV:L), requiring low privileges (PR:L) and no user interaction (UI:N), with low attack complexity. An attacker with local access to a system running a vulnerable Microsoft Office product could supply crafted input that causes the application to dereference a manipulated pointer, leading to arbitrary code execution. No public proof-of-concept code has been identified as of the time of disclosure (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability — an attacker can execute arbitrary code in the context of the affected Office application, potentially gaining full control of the local system. The broad scope of affected products (Office 2016 through 2024, Microsoft 365 Apps for Enterprise, and multiple SharePoint Server versions) means a large enterprise attack surface is exposed. If exploited on a SharePoint Server, the impact could extend to server-side data and services, increasing the risk of lateral movement within an organization (Microsoft MSRC, Feedly).

Mitigation and workarounds

Microsoft released security patches on March 10, 2026, addressing this vulnerability across all affected products. Specific patched versions include: SharePoint Server 2016 (16.0.5543.1000 or later), SharePoint Server 2019 (16.0.10417.20102 or later), SharePoint Server Subscription Edition (16.0.19725.20076 or later), and Office LTSC for Mac 2021/2024 (16.107.26030819 or later). For Office 2016, 2019, 2021, 2024, and Microsoft 365 Apps for Enterprise, updated versions are available via Microsoft's Office Security Releases page at https://aka.ms/OfficeSecurityReleases. Organizations should apply these patches immediately, prioritizing internet-facing SharePoint Server deployments (Microsoft MSRC).

Community reactions

CVE-2026-26113 was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets including Tenable, Qualys, Rapid7, Sophos, Malwarebytes, and KrebsOnSecurity, which collectively noted the March 2026 update cycle as notable for addressing 83 CVEs including two publicly disclosed zero-days (not this CVE). CSO Online specifically highlighted three high-severity Microsoft Office holes patched in March 2026. Windows Central published commentary on the local code execution risk posed by the Office vulnerabilities, noting their relevance beyond IT professionals (Tenable Blog, Rapid7 Blog, Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management