Microsoft’s March Patch Tuesday release fixed roughly 80+ vulnerabilities, including a critical Microsoft Excel information disclosure flaw tracked as CVE-2026-26144. The issue is described as a cross-site scripting (XSS) condition that can be exploited in a zero-click scenario to trigger Copilot Agent mode to exfiltrate data via unintended network egress, creating a path for silent theft of sensitive information commonly stored in spreadsheets (e.g., financials, IP, operational records). Reporting noted the exploit requires network access but does not require user interaction or privilege escalation.
Security guidance emphasized prioritizing patch deployment for CVE-2026-26144 and, where patching must be delayed, reducing exposure by constraining outbound connectivity and watching for anomalous Excel-initiated traffic. Suggested mitigations included restricting outbound network traffic from Office applications, monitoring unusual network requests generated by Excel processes, and disabling or limiting Copilot Agent until the fix is applied. Separate high-priority fixes highlighted in the same Patch Tuesday cycle included SQL Server elevation of privilege (CVE-2026-21262) and a .NET denial-of-service issue (CVE-2026-26127).

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-10, Expel said attackers were actively exploiting an old, unpatched vulnerability in the abandoned Kaswara Modern WPBakery Page Builder WordPress plugin. According to the report, the flaw was being used to upload and run malicious PHP, compromise sites, and deploy XMRig cryptomining malware.
On 2026-03-10, security coverage and analysis emphasized that CVE-2026-26144 in Microsoft Excel could abuse Copilot Agent mode to exfiltrate sensitive data via unintended network egress without user interaction. Reports noted the issue was especially concerning in enterprise environments and suggested mitigations such as restricting Office outbound traffic and limiting Copilot Agent use until patched.
On 2026-03-10, Microsoft released its March Patch Tuesday updates, addressing dozens of vulnerabilities across products including Excel, .NET, SQL Server, and Office. The release included the zero-click Excel information disclosure flaw CVE-2026-26144 and other publicly known issues not reported as actively exploited at disclosure time.
Expel noted that the same Kaswara plugin vulnerability had previously been tied to large botnet campaigns in 2021. Those campaigns reportedly used NDSW/BNTS malware to inject malicious redirects into thousands of WordPress sites worldwide.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
expel.com
Open sourcego.theregister.com
Open sourceconnect.tenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.