CVE-2026-26144
vulnerability analysis and mitigation

Overview

CVE-2026-26144 is a Cross-Site Scripting (XSS) vulnerability in Microsoft Office Excel that allows an unauthorized network attacker to disclose sensitive information. The flaw is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation) and affects Microsoft 365 Apps for Enterprise (both x64 and x86 versions, version 16.0.1 and potentially others). It was publicly disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. The CVSS v3.1 base score is 4.7 (Medium) per the NVD/Microsoft advisory, though ENISA rates it at 7.5 (High) with a different scoring methodology (Microsoft MSRC, Feedly).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), enabling XSS within Microsoft Office Excel. The attack vector is network-based, requires no privileges, and has low attack complexity, though user interaction is required (e.g., opening a malicious Excel file or interacting with a crafted document). A notable aspect of this vulnerability is its interaction with Microsoft Copilot agent functionality — a crafted Excel file can weaponize the Copilot agent to silently exfiltrate data in what has been described as a "zero-click" information disclosure scenario once the file is opened. Technical write-ups indicate the XSS payload can be embedded in Excel content that is rendered in a web context, allowing script execution and data exfiltration (CyberSecSentinel, TechRadar).

Impact

Successful exploitation results in unauthorized information disclosure over a network, with confidentiality impact rated as low-to-high depending on the scoring authority. There is no integrity or availability impact. The most significant concern is the potential for sensitive data exfiltration from Microsoft 365 Apps for Enterprise environments, particularly through the Copilot agent integration, which can act as an unwitting conduit for data theft. Organizations with Microsoft 365 Copilot enabled are at elevated risk, as the vulnerability can be chained with AI agent capabilities to silently exfiltrate spreadsheet data without additional user interaction beyond opening the file (CyberSecSentinel, Feedly).

Exploitability

The EPSS score is approximately 0.095% (low probability of exploitation in the near term). Feedly threat intelligence notes that exploitation has been reported by various sources including cybersecsentinel.com, and agentic malware (referenced as "Agentic") has been reported to have weaponized this vulnerability for data exfiltration. A reference to a proof-of-concept exists at cybersecsentinel.com, though it is described more as a technical write-up than a weaponized exploit. The vulnerability is not currently listed in the CISA KEV catalog based on available data. Multiple Patch Tuesday roundups from March 2026 noted this as one of two publicly disclosed zero-days in that cycle (Feedly, The Hacker News).

Exploitation steps

  1. Craft malicious Excel file: Create a Microsoft Excel document containing an XSS payload embedded in a cell, named range, or metadata field that is rendered in a web context (e.g., when previewed via browser or processed by Copilot agent).
  2. Deliver the file: Distribute the malicious Excel file to the target via phishing email, shared drive, or other social engineering vector, enticing the victim to open it in Microsoft 365 Apps for Enterprise.
  3. Trigger XSS execution: When the victim opens the file, the embedded script executes in the context of the Excel web rendering environment or Copilot agent session, bypassing input sanitization.
  4. Leverage Copilot agent: If Microsoft 365 Copilot is enabled, the XSS payload can instruct the Copilot agent to access and exfiltrate sensitive spreadsheet data or other accessible information without further user interaction.
  5. Exfiltrate data: The malicious script sends captured data (e.g., spreadsheet contents, session tokens) to an attacker-controlled server over the network, completing the information disclosure (CyberSecSentinel, TechRadar).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from Office processes (e.g., EXCEL.EXE) to unknown or suspicious external domains shortly after opening an Excel file; unusual data exfiltration patterns from Microsoft 365 environments.
  • Logs: Microsoft 365 audit logs showing anomalous Copilot agent activity or data access events triggered by Excel file interactions; browser/WebView logs showing script execution originating from Excel content.
  • File System: Suspicious Excel files (.xlsx, .xlsm) received via email or downloaded from untrusted sources containing unusual named ranges, metadata, or embedded web content with script tags.
  • Process: Unusual network connections initiated by EXCEL.EXE or Microsoft 365 Copilot agent processes; unexpected child processes or script interpreters spawned in association with Excel sessions (CyberSecSentinel).

Mitigation and workarounds

Microsoft released a security patch on March 10, 2026, as part of the March 2026 Patch Tuesday update. Affected users should update Microsoft 365 Apps for Enterprise (both x64 and x86) to the latest version via Windows Update or the Microsoft Update Catalog (see https://aka.ms/OfficeSecurityReleases). As a workaround, organizations may consider disabling or restricting Microsoft 365 Copilot agent access for users who cannot immediately patch, and enforcing Protected View for Excel files received from external sources. Nessus plugin 301778 and Qualys detection ID 110521 are available for vulnerability scanning (Microsoft MSRC, Feedly).

Community reactions

The vulnerability attracted notable attention due to its novel attack chain involving Microsoft Copilot agents. TechRadar described it as a "fascinating" flaw that "teams up spreadsheets and Copilot agent to steal data," highlighting the emerging risk of AI agent integration in productivity software. The Register covered it as a "zero-click Microsoft info disclosure bug," emphasizing the low barrier to exploitation. Security researchers on Reddit's r/netsec discussed a common architectural pattern across multiple Q1 2026 vulnerabilities involving AI agent abuse. Cisco Talos, Qualys, Rapid7, Sophos, and Arctic Wolf all included it in their March 2026 Patch Tuesday roundups, with several flagging it as noteworthy due to the Copilot angle (TechRadar, The Register, Talos).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management