Research
CVE-2026-26144: Microsoft Excel Copilot Agent Mode Enables Zero-Click Data Exfiltration — March 2026 Patch Tuesday
Microsoft's March 2026 Patch Tuesday (79 flaws, 2 zero-days) includes CVE-2026-26144, a Critical information disclosure vulnerability where Excel's Copilot Agent mode silently exfiltrates data with no user interaction. An attacker can trigger unintended network egress from the Copilot Agent by crafting a malicious document, leaking PII or credentials without victim action. Patch immediately; the zero-click nature makes this among the highest-urgency findings for organizations using Microsoft 365 Copilot.
↳ Follow the thread