Critical Microsoft Excel bug weaponizes Copilot Agent
- On Tuesday, Microsoft issued its March 2026 Patch Tuesday, addressing 83 vulnerabilities including the critical Microsoft Excel flaw CVE-2026-26144.
- The March release arrived amid a relative lull, with no actively exploited zero-day vulnerabilities and six defects Microsoft described as more likely to be exploited.
- Security researchers flagged two Office remote-code-execution bugs, CVE-2026-26110 and CVE-2026-26113, which can run arbitrary code via the Preview Pane.
- Administrators should restrict outbound Office traffic, monitor Excel network requests, and disable Copilot Agent until patched, as Action1 CEO and co-founder Alex Vovk told The Register, 'Information disclosure vulnerabilities are especially dangerous in corporate environments where Excel files often contain financial data, intellectual property, or operational records.'
- Security commentators noted the AI-attack component in the vulnerability is likely to become more common, with more than half of this month's defects capable of privilege escalation, reflecting broader risks.
18 Articles
18 Articles
Critical Microsoft Excel bug weaponizes Copilot Agent
Could steal sensitive personal and financial data After a whopper of a Patch Tuesday last month, with six Microsoft flaws exploited as zero-days, March didn't exactly roar in like a lion. Just two of the 83 Microsoft CVEs released on Tuesday are listed as publicly known, and none is under active exploitation, which we're sure is a welcome change to sysadmins.…
Microsoft’s monthly Patch Tuesday is first in 6 months with no actively exploited zero-days
Microsoft addressed 83 vulnerabilities that cut across its broad portfolio of enterprise software and underlying services in its latest security update. The company’s Patch Tuesday release contained no actively exploited zero-day vulnerabilities and six defects it described as more likely to be exploited. The vendor’s batch of patches marks the first monthly update without an actively exploited zero-day in six months. The “lack of bugs under ac…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








