Tekmono
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
No Result
View All Result
Tekmono
No Result
View All Result
Home News
Microsoft Releases 83 Vulnerabilities, 8 Rated Critical

Microsoft Releases 83 Vulnerabilities, 8 Rated Critical

by Tekmono Editorial Team
11/03/2026
in News
Share on FacebookShare on Twitter

Microsoft released 83 common vulnerabilities and exposures in March, with two listed as publicly known and none under active exploitation, including a critical information disclosure vulnerability in Microsoft Excel.

This Excel flaw, designated CVE-2026-26144, allows an attacker to cause the Copilot Agent to exfiltrate data via unintended network egress without user interaction. The vulnerability has significant implications for corporate environments where Excel files often contain sensitive financial data and intellectual property.

Zero Day Initiative chief bug hunter Dustin Childs described the vulnerability as “fascinating.” Childs noted that “an attack scenario we’re likely to see more often” now involves AI-assisted exploitation.

Related Reads

Meta Unveils New AI Tools to Fight Scammers

Fortnite’s Save the World Mode Goes Free-to-Play

TikTok and Apple Music Launch Full Song Playback

Open Mac Pages Files on Android Easily

Microsoft stated that CVE-2026-26144 requires network access to exploit but no user interaction or privilege escalation. Action1 CEO Alex Vovk stated that information disclosure vulnerabilities are especially dangerous in corporate settings because attackers could silently extract confidential information without triggering obvious alerts.

Two other critical Office remote code execution bugs, CVE-2026-26110 and CVE-2026-26113, can be triggered via the Preview Pane. This mechanism allows an attacker to exploit the system without a user fully opening a malicious file.

CVE-2026-26110 is a type confusion flaw in Microsoft Office that allows a remote attacker to execute code locally. CVE-2026-26113 is an untrusted pointer dereference flaw that also allows remote attackers to execute code locally.

Jack Bicer, director of vulnerability research at Action1, stated that when a document preview triggers code execution, attackers gain a doorway directly into the system. Childs stated that these Preview Pane exploits have become increasingly common over the last year and it is just a matter of time until they appear in active exploits.

Two vulnerabilities are listed as publicly known but not exploited. CVE-2026-26127 is an out-of-bounds read issue in .NET that allows an unauthorized attacker to deny service over a network. Microsoft assessed that exploitation is unlikely.

CVE-2026-21262 is an improper access control flaw in SQL Server allowing an authorized attacker to elevate privileges over a network. Microsoft stated this flaw is “less likely” to be exploited in the wild.

Microsoft released a total of eight critical-rated CVEs in March. None of the vulnerabilities released in March are currently under active exploitation.

ShareTweet

You Might Be Interested

Meta Unveils New AI Tools to Fight Scammers
News

Meta Unveils New AI Tools to Fight Scammers

11/03/2026
Fortnite’s Save the World Mode Goes Free-to-Play
News

Fortnite’s Save the World Mode Goes Free-to-Play

11/03/2026
TikTok and Apple Music Launch Full Song Playback
News

TikTok and Apple Music Launch Full Song Playback

11/03/2026
Open Mac Pages Files on Android Easily
News

Open Mac Pages Files on Android Easily

11/03/2026
Please login to join discussion

Recent Posts

  • Meta Unveils New AI Tools to Fight Scammers
  • Fortnite’s Save the World Mode Goes Free-to-Play
  • TikTok and Apple Music Launch Full Song Playback
  • Open Mac Pages Files on Android Easily
  • Meta Acquires Moltbook, AI Social Network Platform

Recent Comments

No comments to show.
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
Tekmono is a Linkmedya brand. © 2015.

No Result
View All Result
  • News
  • Guides
  • Lists
  • Reviews
  • Deals