After a whopper of a Patch Tuesday last month, with six Microsoft flaws exploited as zero-days, March didn't exactly roar in like a lion. Just two of the 83 Microsoft CVEs released on Tuesday are listed as publicly known, and none is under active exploitation, which we're sure is a welcome change to sysadmins. Another eight of the 83 Microsoft CVEs are considered critical, and one of these - to quote Zero Day Initiative chief bug hunter Dustin Childs - is "fascinating." Plus, it's got an AI-attack component, so we're going to start with it. CVE-2026-26144 is a critical-severity information disclosure vulnerability in Microsoft Excel. This cross-site scripting flaw can be exploited to "cause Copilot Agent mode to exfiltrate data via unintended network egress, enabling a zero-click information disclosure attack," Redmond warned. Yes, you read that right: a zero-click bug that weaponizes an Excel spreadsheet and the Copilot Agent to steal data. As Childs notes, it's "an attack scenario we're likely to see more often." This bug requires network access to exploit, but no user interaction or privilege escalation. "Information disclosure vulnerabilities are especially dangerous in corporate environments where Excel files often contain financial data, intellectual property, or operational records," Action1 CEO and co-founder Alex Vovk told The Register. "If exploited, attackers could silently extract confidential information from internal systems without triggering obvious alerts." P...
Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack
Affected Software
Frequently Asked Questions
What is the main topic of this article?
The article discusses a critical Microsoft Excel vulnerability that enables zero-click information disclosure attacks using the Copilot Agent.
What security implications are discussed?
The article highlights the potential risks associated with zero-click attacks that exploit the Excel vulnerability, leading to unauthorized information disclosure.
What products or software are affected?
The affected software includes Microsoft Excel, Microsoft Office, Microsoft .NET, and Microsoft SQL Server, specifically certain versions of each.
What versions of Microsoft products are impacted by the vulnerability?
The vulnerability affects Microsoft Excel version 2026-26144, Microsoft Office versions 2026-26110 and 2026-26113, Microsoft .NET version 2026-26127, and SQL Server version 2026-21262.
What actions should users take regarding the identified vulnerabilities?
Users should apply the latest security patches provided by Microsoft to mitigate the risks associated with these vulnerabilities.