Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26144
https://www.malwarebytes.com/blog/news/2026/03/march-2026-patch-tuesday-fixes-two-zero-day-vulnerabilities
https://www.helpnetsecurity.com/2026/03/11/march-2026-patch-tuesday/
https://thehackernews.com/2026/03/microsoft-patches-84-flaws-in-march.html
https://www.theregister.com/2026/03/10/zeroclick_microsoft_info_disclosure_bug/
https://cyberscoop.com/microsoft-patch-tuesday-march-2026/
Source: Mitre, NVD
Published: 2026-03-10
Updated: 2026-03-13
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 4.7
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
EPSS: 0.00095