CVE-2026-26144Patch(microsoft / 365_apps)

MEDIUMCVSS 4.7 · MEDIUM

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps

Threat summary

  • Active exploitation appears in 5 classified signals
  • Patch or workaround signal is available
  • 48 mentions across 21 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 5 signals
  • Patch or workaround mentioned in 25 signals
  • Technical details provided in 41 signals
  • Disclosure: 14 classified signals
  • General: 10 classified signals
  • Peaked 19d ago at 15 mentions (2026-03-11); latest day: 1
  • 48 total mentions across 21 days

Affected systems

Vendors
Products
365_apps

1 version affected across 1 product

Deep dive

Activity timeline48 mentions / 21d
0481115Mentions · 2026-03-10: 3Mentions · 2026-03-11: 15Mentions · 2026-03-12: 5Mentions · 2026-03-13: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 4Mentions · 2026-03-17: 1Mentions · 2026-03-18: 2Mentions · 2026-03-19: 2Mentions · 2026-03-23: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 2Mentions · 2026-03-29: 1Mentions · 2026-03-31: 1Mentions · 2026-04-06: 1Mentions · 2026-04-17: 1Mentions · 2026-04-19: 1Mentions · 2026-04-23: 2Mentions · 2026-04-29: 1Mentions · 2026-05-14: 1Mentions · 2026-06-02: 1Active Exploitation · 2026-03-11: 3Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-04-17: 1Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-11: 8Patch / Workaround · 2026-03-12: 5Patch / Workaround · 2026-03-16: 3Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-03-10: 3Technical Details · 2026-03-11: 10Technical Details · 2026-03-12: 5Technical Details · 2026-03-13: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 4Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 2Technical Details · 2026-03-23: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-29: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-02: 103-1003-1203-1503-1703-1903-2503-2904-0604-1904-2906-02
Signal classification4 categories
Patch
2245.8%
Disclosure
1429.2%
General
1020.8%
Active Exploitation
24.2%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-103
Disclosure1Patch2
2026-03-1115
Active Exploitation1Disclosure3General4Patch7
2026-03-125
Disclosure1Patch4
2026-03-131
Disclosure1
2026-03-151
General1
2026-03-164
Disclosure1Patch3
2026-03-171
Disclosure1
2026-03-182
Disclosure1Patch1
2026-03-192
General1Patch1
2026-03-231
Disclosure1
2026-03-251
Patch1
2026-03-262
Patch2
2026-03-291
General1
2026-03-311
Disclosure1
2026-04-061
Disclosure1
2026-04-171
Active Exploitation1
2026-04-191
Patch1
2026-04-232
Disclosure1General1
2026-04-291
Disclosure1
2026-05-141
General1
2026-06-021
General1
Full discourse20 posts
  • SoyITPro@SoyITPro
    Patch

    🔒 Updates – Marzo 2026 Microsoft corrige 84 fallos, incluyendo 8 críticos en Windows, Office, SQL Server, .NET y Azure: 🛑 CVE-2026-26127 (.NET) – Denegación de servicio por lectura fuera de límites. 📊 CVE-2026-21262 (SQL Server) – Escalada de privilegios hasta SQLAdmin. 📄 CVE-2026-26113 (Office) – RCE por puntero no confiable (CVSS 8.4) 📄 CVE-2026-26110 (Office) – RCE por confusión de tipos, explotable vía Panel de Vista Previa. 📊 CVE-2026-26144 (Excel) – Divulgación de información sensible en generación web. 🌐 CVE-2026-23654 (GitHub/PyPI) – RCE por dependencia maliciosa en paquetes de terceros. #Security #Windows #Updates

    Post summary

    Microsoft released a March‑2026 update fixing 84 vulnerabilities, including critical flaws that cause denial‑of‑service, privilege escalation, and remote code execution across Windows, Office, SQL Server, .NET, and Azure; pivotal issues include an RCE via a malicious third‑party dependency.

    0703131.3K
    12.3K followersView on X
  • TrendAI Zero Day Initiative@thezdi
    Disclosure

    And don't miss our bug of the month! Each patch Tuesday we'll be selecting our very favorite patch to highlight. This month, it CVE-2026-26144 - a Critical-rated info disclosure in Excel that uses the Copilot Agent to exfiltrate data. Neat! https://t.co/2UC9cOz15c

    Post summary

    The tweet announces CVE‑2026‑26144 as a critical information disclosure in Excel, providing limited technical details but no evidence of PoC, exploit, or patch.

    1111257.6K
    86.1K followersView on X
  • Haifei Li@HaifeiLi
    General

    Seems interesting one indeed, but why MSRC says the exploitation is unlikely? Usually such XSS is logical bug which should already have working exploit in place? Anyone get more details? https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26144

    Post summary

    The user asks why MSRC declares exploitation unlikely for CVE‑2026‑26144 and requests additional details, but the commentary contains no PoC, exploit code, patch info, or technical specifics.

    0001033.1K
    8.3K followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    A new Microsoft Excel vulnerability just exposed something bigger about AI security. Security researchers discovered CVE-2026-26144, a flaw that could allow attackers to exfiltrate sensitive data through Microsoft Copilot. No malware required. Here’s how the attack works 👇 • A malicious Excel file contains hidden content • Copilot processes the spreadsheet normally • The AI assistant can be tricked into sending sensitive data externally Researchers say this could expose: • Financial spreadsheets • Internal reports • Business data handled by Copilot This vulnerability was patched during Microsoft’s March Patch Tuesday, but it reveals something important: AI assistants are now part of the attack surface. Security teams must start defending not just systems… …but the AI tools that access company data. Welcome to the era of AI-driven attack vectors.

    Post summary

    Microsoft Excel’s CVE‑2026‑26144 enables Copilot‑mediated data exfiltration; Microsoft patched it in March, underscoring the need to secure AI assistants that access corporate data.

    51020107
    808 followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    ⚠️ PATCH NOW: Microsoft just fixed 83 vulnerabilities in the March 2026 Patch Tuesday update. Some highlights security teams should pay attention to: • CVE-2026-26144 – Excel flaw that can leak sensitive data through Copilot with zero user interaction • CVE-2026-26110 / CVE-2026-26113 – Microsoft Office RCE triggered just by previewing a malicious file • CVE-2026-21262 – SQL Server privilege escalation over network The real lesson: Attackers don’t always need malware anymore. Sometimes they just need: 📄 One document 👀 One preview pane 💥 One unpatched system Patch management isn’t boring it’s your first line of defense. #CyberSecurity #PatchTuesday #ThreatInte

    Post summary

    The post is a patch‑tuesday alert urging organizations to apply Microsoft’s March 2026 update, highlighting how simple document previews can trigger severe RCE and privilege escalation vulnerabilities.

    60010120
    808 followersView on X
  • /r/netsec@_r_netsec
    General

    Common architectural pattern across four Q1 2026 AI assistant vulnerabilities (CVE-2026-26144, CVE-2026-0628, CVE-2026-24307, PleaseFix) https://blog.barrack.ai/ai-copilot-attack-surface/

    Post summary

    The tweet references four Q1 2026 AI assistant CVEs and links to a blog about their common architectural pattern, but provides no additional details or actionable information.

    03030586
    32.8K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    📊 CVE-2026-26144 Excel flaw: Copilot data leak zero-click via preview. High sev, AI risk rising—patch Office! https://www.youtube.com/watch?v=4UBLCZk8aMQ

    Post summary

    The message highlights a high‑severity Excel flaw (CVE‑2026‑26144) that enables zero‑click Copilot data leaks via preview, urging users to apply patches to Microsoft Office.

    00040189
    437 followersView on X
  • SECUREU@secureu_in
    Patch

    Microsoft's own AI just became the attack vector. A vulnerability in Excel lets attackers weaponise Copilot to silently exfiltrate your data. Zero clicks. Zero warnings. Your AI assistant sends your files to the attacker. CVE-2026-26144. Patch now. 🧵 https://t.co/Af4it9YZ8l

    Post summary

    The tweet warns that CVE‑2026‑26144 in Excel lets attackers weaponise Copilot to exfiltrate data silently and urges users to apply the available patch.

    1102061
    237 followersView on X
  • Gerardo I. Ornelas@gerardoiornelas
    Patch

    Copilot was supposed to help you work. Instead, it became an exfiltration channel. Microsoft just patched CVE-2026-26144: an XSS flaw in Excel that let Copilot Agent mode silently send your workbook data to attackers. Zero clicks. No macros. This is what ambient authority looks like in practice. Copilot had document read access AND network egress. There was no execution boundary between "read my spreadsheet" and "send it to someone." Execution-time authorization is the missing control plane. #AIAgentSecurity #ExecutionTimeAuthorization #AmbientAuthority

    Post summary

    Microsoft patched CVE-2026-26144, an XSS flaw in Excel used by Copilot Agent mode to exfiltrate workbook data; the post gives technical details but no evidence of active exploitation or PoC.

    1101047
    340 followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    The vulnerability is tracked as CVE-2026-26144 and affects Microsoft Excel + Copilot integration. Microsoft addressed it in the March 2026 Patch Tuesday update, but many organizations delay patching which is where attackers usually strike.

    Post summary

    Microsoft released a patch for CVE‑2026‑26144, which targets the Excel + Copilot integration; organizations that postpone patching leave themselves vulnerable to potential exploitation.

    0102077
    808 followersView on X
  • Nik Kale@nik_kale
    General

    New piece in Dark Reading on why the agentic AI era did not create new vulnerabilities, it amplified all the existing ones. Anchor case: CVE-2026-26144. A simple XSS in Excel becomes a full chain into Copilot Agent that exfiltrates document contents to an attacker-controlled server. The same XSS that has been on the OWASP Top 10 for two decades. The pattern is consistent across every agentic system I've worked with. Old vulnerability classes, new blast radius. Your AppSec program does not need new categories, it needs new severity scoring that accounts for what agents do with the access they're given. https://www.darkreading.com/vulnerabilities-threats/every-old-vulnerability-ai-vulnerability

    Post summary

    The article discusses the amplification of an existing XSS vulnerability (CVE‑2026‑26144) in agentic AI systems such as Copilot, emphasizing the need for updated severity scoring, but it does not provide PoC, exploit, or patch information.

    0020088
    397 followersView on X
  • Darshan Yadav@DarshanSays
    Disclosure

    @satyanadella Great milestone. One thing to track: agent mode means Copilot takes action in Excel, not just assists. Different trust model entirely. CVE-2026-26144 showed crafted content can turn Copilot Agent into an exfiltration channel. Rollout needs matching threat awareness.

    Post summary

    The tweet announces CVE‑2026‑26144, noting that crafted content can hijack Copilot Agent into an exfiltration channel, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    000111.3K
    22 followersView on X
  • Gerardo I. Ornelas@gerardoiornelas
    Disclosure

    The Microsoft Copilot incident (CVE-2026-26144) reveals a pattern we're seeing across the agent landscape: Langflow: default allow_dangerous_code=True exposed REPL to prompts Copilot in Excel: XSS -> data exfiltration without user interaction These are not isolated bugs. They're systemic control failures. The root cause is the same: execution boundaries were never enforced at the point of action. Ambient authority is the systemic flaw. Execution-time authorization is the fix. #SecureAgents #ExecutionBoundary #AgentSecurity

    Post summary

    The post announces and details the Microsoft Copilot CVE‑2026‑26144, highlighting XSS‑based data exfiltration and systemic control failures, but provides no PoC, exploit code, or patch information.

    0101045
    340 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Disclosure

    🎙️ RadioCSIRT Ép.595 – Épisode Spécial du jeudi 12 mars 2026 Un seul sujet. Un cycle qui marque l'histoire des CVE : le Patch Tuesday Microsoft de mars 2026. 🔴 Microsoft Patch Tuesday – 79 vulnérabilités corrigées, deux zero-days publiquement divulgués. CVE-2026-26113 et CVE-2026-26110 : deux RCE critiques dans Microsoft Office déclenchables par simple visualisation d'un message dans le volet de prévisualisation, sans interaction utilisateur. 🔴 CVE-2026-26144 – Microsoft Excel et Copilot Agent Mode. Divulgation d'informations critique : un attaquant peut forcer Copilot à exfiltrer des données via un trafic réseau non prévu. Attaque zero-click documentée. 🔴 CVE-2026-21262 – SQL Server, élévation de privilèges jusqu'au niveau sysadmin via le réseau (CVSS 8.8). Zero-day publiquement divulgué avant correctif. CVE-2026-26127 – .NET, déni de service réseau sans authentification. 🔴 Six vulnérabilités Important signalées comme prioritaires par Cisco Talos et Tenable : Windows Graphics Component, Windows Kernel, Windows Accessibility Infrastructure, Windows SMB Server, Ancillary Function Driver for WinSock, Winlogon (découverte par Google Project Zero). 🔴 CVE-2026-21536 – CVSS 9.8 Critical. Première CVE officiellement attribuée à un agent IA autonome : XBOW, agent de penetration testing entièrement automatisé, sans accès au code source. Microsoft a corrigé côté serveur, sans action requise des utilisateurs. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-595-episode-special-patch-tuesday-microsoft-mars-2026/ 📖 Analyse complète sur le blog : https://blog.marcfredericgomez.fr/microsoft-patch-tuesday-mars-2026-79-vulnerabilites-corrigees-deux-zero-days-divulgues/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #PatchTuesday #Microsoft #CVE #ZeroDay #RCE #Windows #Office #SQLServer #Copilot #AI #XBOW #PatchManagement #VulnerabilityManagement #InfoSec #CERT #CSIRT #SOC #CISO #VOC #Patch

    Post summary

    The post announces Microsoft’s March 2026 Patch Tuesday, listing 79 vulnerabilities—including two zero‑days—alongside technical details and patch status, indicating a disclosure-focused update.

    0002060
    413 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة حرجة في Microsoft Excel تستغل Copilot Agent لكشف المعلومات كشفت تحديثات "Patch Tuesday" عن ثغرة حرجة في Microsoft Excel (ضمن CVE-2026-26144) تُمكّن من تنفيذ هجوم "zero-click" لكشف المعلومات الحساسة. تستغل هذه الثغرة، التي تُصنف ضمن 83 إصلاحاً أمنياً لي Copilot Agent لتسهيل استخراج البيانات دون تفاعل المستخدم. تُشير خطورة الثغرة إلى قدرتها على التسبب في اختراق واسع النطاق للمعلومات. يُنصح بتطبيق جميع التحديثات الأمنية الصادرة عن Microsoft فوراً. 🔗 للمزيد: https://go.theregister.com/feed/www.theregister.com/2026/03/10/zeroclick_microsoft_info_disclosure_bug/

    Post summary

    Microsoft disclosed CVE‑2026‑26144, a zero‑click information‑disclosure flaw in Excel that exploits Copilot Agent. Immediate patching of all relevant updates is strongly advised.

    00020235
    68 followersView on X
  • Antonio Gambina@Lago72
    Disclosure

    🔐 Every old vulnerability is now an AI vulnerability. Microsoft's March 2026 patch (CVE-2026-26144) shows XSS can hijack Copilot Agent to exfiltrate data silently. Traditional security models are broken. https://buff.ly/a4ses0p v/ @DarkReading #CyberSecurity #Infosec https://t.co/dyz3QxjYyG

    Post summary

    The post announces Microsoft’s patch for CVE‑2026‑26144, detailing an XSS flaw that allows hijacking of the Copilot Agent to silently exfiltrate data.

    0001056
    10.9K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2026-3888 3 - CVE-2026-40372 4 - CVE-2025-59536 5 - CVE-2026-26144 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVE identifiers as trending, but provides no further technical or operational details.

    00010472
    1.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Microsoft patched CVE-2026-26144, an XSS flaw in Excel that exploits Copilot Agent to silently exfiltrate data. AI amplifies classic vulnerabilities, requiring new monitoring and egress controls. #AIExploits #DataLeak #USA https://ift.tt/Mo3qsAO

    Post summary

    The tweet announces that Microsoft has patched CVE‑2026‑26144, an XSS flaw in Excel enabling Copilot Agent‑based data exfiltration, and underscores the need for new monitoring controls.

    00010238
    4.1K followersView on X
  • 松下健太郎|㍿クライムドア代表@climbdoor_com
    Disclosure

    3月のMicrosoft月例パッチから! 今月特に注目したいのが、Excelの脆弱性(CVE-2026-26144)。 なんと攻撃者がこれを利用して「Copilot Agent」にデータを外部送信させる可能性があるとのこと。 AIが便利な「相棒」になる一方で、 そこが新たな攻撃の手口になるリスクは、もはや前提として考えなければなりませんね。 https://www.trendmicro.com/ja_jp/research/26/c/the-march-2026-security-update-review.html

    Post summary

    Trend Micro highlights the March 2026 Microsoft patch, revealing that Excel CVE‑2026‑26144 could allow attackers to send data from Copilot Agent to external destinations, though no proof of exploitation or patch details are provided.

    00010281
    911 followersView on X
  • AI Cyber Quest@aicyberquest_in
    General

    CVE-2026-26144 is a critical vulnerability in Microsoft Excel that allows data exfiltration through AI assistants like Copilot. Your AI tools could be leaking sensitive data without your knowledge. #CVE202626144 #AISecurity #DataLeak

    Post summary

    The text warns of a purported critical Excel CVE that could leak data via AI assistants, yet it offers no PoC, exploit details, patch info, or evidence of active exploitation.

    100007
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86

Explore more