logo

Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack

ID: 5a114d2d-f35d-5815-bb7d-eb6adda9240b

STIX ID: report--5a114d2d-f35d-5815-bb7d-eb6adda9240b

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-03-10

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft's March 2026 Patch Tuesday addresses multiple vulnerabilities, notably CVE-2026-26144 — a critical Excel cross-site scripting/information-disclosure flaw that can cause Copilot Agent to exfiltrate data in a zero-click scenario — plus Office remote code execution flaws (Preview Pane) and other CVEs; the report emphasizes high impact to corporate data, required mitigations (patching, limiting outbound Office network access, monitoring Excel network activity, disabling Copilot Agent), and notes that these are not reported as actively exploited at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.