CVE-2026-26113Patch(microsoft / 365_apps)

MEDIUMCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-822

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office
  • office_long_term_servicing_channel
  • sharepoint_server

Threat summary

  • Active exploitation appears in 4 classified signals
  • Patch or workaround signal is available
  • 16 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 16 signals
  • Disclosure: 4 classified signals
  • Peaked 6d ago at 6 mentions (2026-03-11); latest day: 1
  • 16 total mentions across 8 days

Affected systems

Vendors
Products
365_appsofficeoffice_long_term_servicing_channelsharepoint_server

5 versions affected across 4 products

Deep dive

Activity timeline16 mentions / 8d
02356Mentions · 2026-03-10: 1Mentions · 2026-03-11: 6Mentions · 2026-03-12: 2Mentions · 2026-03-15: 1Mentions · 2026-03-16: 2Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Mentions · 2026-04-25: 1Active Exploitation · 2026-03-11: 3Active Exploitation · 2026-03-12: 1Patch / Workaround · 2026-03-11: 3Patch / Workaround · 2026-03-12: 2Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 6Technical Details · 2026-03-12: 2Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 1Technical Details · 2026-04-25: 103-1003-1103-1203-1503-1603-2003-2104-25
Signal classification3 categories
Patch
956.3%
Disclosure
425.0%
Active Exploitation
318.8%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-116
Active Exploitation3Patch3
2026-03-122
Patch2
2026-03-151
Patch1
2026-03-162
Disclosure1Patch1
2026-03-202
Disclosure1Patch1
2026-03-211
Patch1
2026-04-251
Disclosure1
Full discourse16 posts
  • SoyITPro@SoyITPro
    Patch

    🔒 Updates – Marzo 2026 Microsoft corrige 84 fallos, incluyendo 8 críticos en Windows, Office, SQL Server, .NET y Azure: 🛑 CVE-2026-26127 (.NET) – Denegación de servicio por lectura fuera de límites. 📊 CVE-2026-21262 (SQL Server) – Escalada de privilegios hasta SQLAdmin. 📄 CVE-2026-26113 (Office) – RCE por puntero no confiable (CVSS 8.4) 📄 CVE-2026-26110 (Office) – RCE por confusión de tipos, explotable vía Panel de Vista Previa. 📊 CVE-2026-26144 (Excel) – Divulgación de información sensible en generación web. 🌐 CVE-2026-23654 (GitHub/PyPI) – RCE por dependencia maliciosa en paquetes de terceros. #Security #Windows #Updates

    Post summary

    The tweet announces March 2026 Microsoft security updates that fix eight critical CVEs across Windows, Office, SQL Server, .NET, and third‑party packages, and provides technical details of the vulnerabilities.

    0703131.3K
    12.3K followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    ⚠️ PATCH NOW: Microsoft just fixed 83 vulnerabilities in the March 2026 Patch Tuesday update. Some highlights security teams should pay attention to: • CVE-2026-26144 – Excel flaw that can leak sensitive data through Copilot with zero user interaction • CVE-2026-26110 / CVE-2026-26113 – Microsoft Office RCE triggered just by previewing a malicious file • CVE-2026-21262 – SQL Server privilege escalation over network The real lesson: Attackers don’t always need malware anymore. Sometimes they just need: 📄 One document 👀 One preview pane 💥 One unpatched system Patch management isn’t boring it’s your first line of defense. #CyberSecurity #PatchTuesday #ThreatInte

    Post summary

    The post announces Microsoft’s March 2026 patch update, highlighting critical CVEs such as Excel data leakage, Office RCE, and SQL Server privilege escalation, and urges immediate patching of affected systems.

    60010120
    808 followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    You don't have to open the file. You just have to look at it. Microsoft's March 2026 Patch Tuesday fixed two critical Office vulnerabilities. CVE-2026-26110 and CVE-2026-26113 where the preview pane alone is enough to trigger remote code execution. No clicks. No downloads. Just a file sitting in your inbox. The attacker's job used to be getting you to open something. Now they just need to make sure it lands.

    Post summary

    Microsoft has issued a patch for two Office CVEs (CVE‑2026‑26110 and CVE‑2026‑26113) that let attackers trigger remote code execution via the preview pane without any user interaction, requiring only that the file lands in the inbox.

    1102082
    803 followersView on X
  • Emmanuel Nii Okai@engniiokai
    Disclosure

    You previewed the file. Didn't open it. Didn't click anything. Just hovered over it in Outlook. That was enough. CVE-2026-26113 and CVE-2026-26110 both Critical, both in Microsoft Office, both triggered by the preview pane. Arbitrary code execution. No interaction. The attack lands the moment your eyes do. We built convenience into the kill chain.

    Post summary

    The message details two Microsoft Office CVEs that can be triggered by previewing a file in Outlook, allowing arbitrary code execution without any user interaction.

    1101077
    803 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Patch

    🎙️ RadioCSIRT Ép.595 – Épisode Spécial du jeudi 12 mars 2026 Un seul sujet. Un cycle qui marque l'histoire des CVE : le Patch Tuesday Microsoft de mars 2026. 🔴 Microsoft Patch Tuesday – 79 vulnérabilités corrigées, deux zero-days publiquement divulgués. CVE-2026-26113 et CVE-2026-26110 : deux RCE critiques dans Microsoft Office déclenchables par simple visualisation d'un message dans le volet de prévisualisation, sans interaction utilisateur. 🔴 CVE-2026-26144 – Microsoft Excel et Copilot Agent Mode. Divulgation d'informations critique : un attaquant peut forcer Copilot à exfiltrer des données via un trafic réseau non prévu. Attaque zero-click documentée. 🔴 CVE-2026-21262 – SQL Server, élévation de privilèges jusqu'au niveau sysadmin via le réseau (CVSS 8.8). Zero-day publiquement divulgué avant correctif. CVE-2026-26127 – .NET, déni de service réseau sans authentification. 🔴 Six vulnérabilités Important signalées comme prioritaires par Cisco Talos et Tenable : Windows Graphics Component, Windows Kernel, Windows Accessibility Infrastructure, Windows SMB Server, Ancillary Function Driver for WinSock, Winlogon (découverte par Google Project Zero). 🔴 CVE-2026-21536 – CVSS 9.8 Critical. Première CVE officiellement attribuée à un agent IA autonome : XBOW, agent de penetration testing entièrement automatisé, sans accès au code source. Microsoft a corrigé côté serveur, sans action requise des utilisateurs. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-595-episode-special-patch-tuesday-microsoft-mars-2026/ 📖 Analyse complète sur le blog : https://blog.marcfredericgomez.fr/microsoft-patch-tuesday-mars-2026-79-vulnerabilites-corrigees-deux-zero-days-divulgues/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #PatchTuesday #Microsoft #CVE #ZeroDay #RCE #Windows #Office #SQLServer #Copilot #AI #XBOW #PatchManagement #VulnerabilityManagement #InfoSec #CERT #CSIRT #SOC #CISO #VOC #Patch

    Post summary

    RadioCSIRT’s Patch Tuesday episode reports 79 Microsoft vulnerabilities, including two publicly disclosed zero-day RCEs and a documented zero‑click exploit, all of which have been patched server‑side with no user‑action required.

    0002060
    413 followersView on X
  • CyberSec Intel Alliance@CyberAlliance26
    Patch

    🚨 Critical Alert: CVE-2026-26113 - RCE in Microsoft Office! Attackers can exploit via Preview Pane to run code & compromise systems. Impact: Malware, data theft. Fix: Apply March 2026 patches NOW! #CyberSecurity #PatchTuesday #MicrosoftOffice #Threats #Trending https://t.co/BxyPXezBJr

    Post summary

    The tweet warns of a remote code execution vulnerability (CVE-2026-26113) in Microsoft Office that can be triggered through the Preview Pane and urges users to apply the March 2026 patches immediately.

    0101086
    23 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-26113: Microsoft Office Preview Pane RCE Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04dsvx80

    Post summary

    The headline announces CVE-2026-26113 as a Microsoft Office Preview Pane remote code execution flaw, focusing on business implications and response guidance.

    0000028
    29 followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    CVE-2026-26113 and CVE-2026-26110. Both critical. Both Office. Both sitting in the preview pane your IT team never disabled because "nobody complained." Disable the preview pane in Outlook now — File → Options → Mail → Reading Pane. Takes 11 seconds. (Microsoft MSRC March 2026) When did your org last patch Office? Drop the month below genuinely curious how exposed this thread is.

    Post summary

    The post highlights two critical Office CVEs affecting the Outlook preview pane and recommends disabling that feature as a workaround, indicating that organizations should check their patch status.

    0000062
    800 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26113 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. https://www.cve.org/CVERecord?id=CVE-2026-26113

    Post summary

    The text announces CVE-2026-26113, a local code‑execution vulnerability in Microsoft Office caused by an untrusted pointer dereference.

    00000206
    56.7K followersView on X
  • CybrPulse@CybrPulse
    Patch

    March Patch Tuesday: 77 CVEs, no zero-days. Two Office flaws to prioritize: CVE-2026-26113 and CVE-2026-26110 both trigger RCE just by previewing a message. No clicks needed. Also CVE-2026-24294 (SMB auth bypass). Patch now. https://krebsonsecurity.com/2026/03/microsoft-patch-tuesday-march-2026-edition/ #infosec

    Post summary

    The post highlights Microsoft's March Patch Tuesday, describes RCE exploits in Office and an SMB auth bypass, and urges users to apply the released patches.

    0000053
    19 followersView on X
  • Giulio Sistilli@GiulioSistilli
    Patch

    New CVEs alert: Microsoft just patched 83+ flaws, including 8 Critical ones: • CVE-2026-26110 & CVE-2026-26113: Office RCE via preview pane (CVSS 8.4) • CVE-2026-21262: SQL Server priv esc (publicly disclosed zero-day) • CVE-2026-26127: .NET DoS (another public zero-day) #CVE

    Post summary

    Microsoft released a patch for over 83 vulnerabilities, including 8 critical Office RCEs, a SQL Server privilege escalation, and a .NET denial‑of‑service flaw.

    0000094
    27 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploiting CVE-2026-21262 in SQL Server can gain sysadmin privileges over the network, then pivot laterally to additional systems. Combined with Office RCE flaws like CVE-2026-26113, these create high-risk breach chains. Runtime segmentation helps contain post-compromise lateral movement. 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/microsoft-march-2026-patch-tuesday-fixes-83-cves-including-two-publicly-disclosed-zero-days #ZeroDay #ZeroTrust

    Post summary

    Advisors report that attackers are actively abusing CVE-2026-21262 in SQL Server to gain system administrator rights and move laterally, chaining it with Office RCE flaws (CVE-2026-26113). Runtime segmentation is suggested to limit spreading.

    0000070
    1.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploiting Microsoft Office vulnerabilities (CVE-2026-26110, CVE-2026-26113) demonstrate a classic privilege escalation to lateral movement pattern. Once elevated access is achieved, compromised credentials enable network-wide pivoting. Runtime segmentation helps contain such post-compromise activity. #ZeroDay 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/microsoft-march-2026-patch-tuesday-addresses-83-vulnerabilities-including-two-publicly-disclosed-zero-days

    Post summary

    The post reports that attackers are actively exploiting CVE-2026-26110 and CVE‑2026-26113 in Microsoft Office, using privilege escalation to gain lateral movement and network pivoting.

    0000052
    1.9K followersView on X
  • WindowsForum@windowsforum
    Patch

    🔒 Urgent patch: two Office flaws let attackers run code remotely—install the March 2026 updates now before the chaos starts. #WindowsForum #PatchTuesday #CVE26110 #CVE26113 https://windowsforum.com/threads/urgent-office-patch-fix-cve-2026-26110-and-cve-2026-26113-now.404710/?utm_source=rss&utm_medium=rss

    Post summary

    The post warns that two Office CVEs (CVE‑2026‑26110 and CVE‑2026‑26113) allow remote code execution and urges users to apply the March 2026 updates immediately.

    0000041
    1.0K followersView on X
  • nin_tech@nin_tech_x
    Active Exploitation

    Microsoft Patch Tuesday: 83 CVEs, 2 zero-days. Excel CVE-2026-26144 enables data exfiltration via Copilot. Office CVE-2026-26113/26110 allow RCE via Preview Pane. Google Cloud: attackers now exploit vulnerabilities over credentials. #CyberSecurity #PatchTuesday #Microsoft

    Post summary

    The post reports that Microsoft’s newly disclosed CVEs are being actively exploited for data exfiltration and remote code execution, while attackers are also leveraging Google Cloud vulnerabilities using credentials.

    0000075
    19 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26113 - High Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. https://www.thehackerwire.com/vulnerability/CVE-2026-26113/ https://t.co/nWLQ2Buvea

    Post summary

    CVE-2026-26113 is a high‑severity vulnerability in Microsoft Office that enables local code execution via an untrusted pointer dereference.

    0000036
    133 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftoffice2016-x64
Appmicrosoftoffice2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021macos-
Appmicrosoftoffice_long_term_servicing_channel2024-x64
Appmicrosoftoffice_long_term_servicing_channel2024-x86
Appmicrosoftoffice_long_term_servicing_channel2024macos-
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more