Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.7

Microsoft Office Excel Cross-Site Scripting Flaw Allows Information Disclosure

CVE-2026-26144
Summary

An attacker can use Microsoft Office Excel to steal sensitive information from a network. This happens when a malicious user injects code into an Excel file, which can then be opened by others and used to access unauthorized data. Users should be cautious when opening files from untrusted sources and ensure they have the latest updates installed.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
microsoft 365_apps All versions
microsoft 365_apps All versions
Original title
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Original description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
nvd CVSS3.1 7.5
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 10 Mar 2026 · Updated: 14 Mar 2026 · First seen: 11 Mar 2026