Microsoft Office RCE via Preview Pane (CVE-2026-26110, CVE-2026-26113) — March 2026 Patch Tuesday — Threadlinqs Intelligence
As of 2026-05-30, Microsoft Office RCE via Preview Pane (CVE-2026-26110, CVE-2026-26113) — March 2026 Patch Tuesday is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0211 · Severity: CRITICAL · CVSS: 8.4 · Status: PATCHED · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Two Critical remote code execution vulnerabilities in Microsoft Office (CVE-2026-26110 type confusion, CVE-2026-26113 untrusted pointer dereference) allow attackers to execute arbitrary code via the
Microsoft’s March 2026 Patch Tuesday, released March 11, 2026, addresses 83 vulnerabilities across Windows, Microsoft Office, Azure, SQL Server, .NET, and Chromium-based Edge. Eight vulnerabilities are rated Critical and 75 rated Important. No vulnerabilities were actively exploited at time of release, but two were publicly disclosed zero-days.
The headline threats are CVE-2026-26110 and CVE-2026-26113, both Critical remote code execution vulnerabilities in Microsoft Office exploitable through the Preview Pane. CVE-2026-26110 is a type confusion flaw (CWE-843) caused by access to a resource using an incompatible type, where Office incorrectly handles object types and mistreats a resource as an incompatible type. Attackers craft documents containing malformed objects that cause type confusion, corrupt memory, and enable code execution. CVE-2026-26113 is an untrusted pointer dereference flaw (CWE-822) where Microsoft Office improperly handles memory pointers, allowing manipulation of memory access. Both carry a CVSS score of 8.4 with local attack vector, low complexity, no privileges required, and no user interaction needed. The Preview Pane serves as the attack vector for both, meaning users can be compromised simply by previewing a malicious document in Outlook, Windows Explorer, or other applications that render document previews. Critically, hiding the Preview Pane in Outlook may not fully mitigate these attacks. Zero Day Initiative’s Dustin Childs warns these Preview Pane vulnerabilities continue appearing regularly and “it’s just a matter of time until they start appearing in active exploits.”
CVE-2026-26144 is a Critical information disclosure vulnerability in Microsoft Excel (CVSS 7.5) caused by improper neutralization of input during web page generation (cross-site scripting). What makes this vulnerability exceptional is its ability to weaponize Copilot Agent mode: an attacker can exploit the XSS flaw to cause Copilot Agent to exfiltrate data via unintended network egress, enabling a zero-click information disclosure attack. No user interaction or privileges are needed. This represents an emerging attack pattern where AI assistant features amplify the impact of traditional web vulnerabilities.
Two publicly disclosed zero-days were patched: CVE-2026-21262, an elevation of privilege vulnerability in SQL Server (CVSS 8.8) caused by improper access control that enables attackers to gain SQL sysadmin privileges; and CVE-2026-26127, a denial of service vulnerability in .NET 9.0 and 10.0 (CVSS 7.5) caused by an out-of-bounds read.
Six privilege escalation vulnerabilities were flagged by Microsoft as “more likely to be exploited”: CVE-2026-23668 (Windows Graphics Component), CVE-2026-24289 (Windows Kernel, use-after-free, SYSTEM access), CVE-2026-24291 (Windows Accessibility Infrastructure ATBroker.exe), CVE-2026-24294 (Windows SMB Server), CVE-2026-25187 (Winlogon), and CVE-2026-26132 (Windows Kernel, use-after-free). Additionally, CVE-2026-23669 is a Windows Print Spooler RCE (CVSS 8.8) caused by a use-after-free flaw similar to PrintNightmare, allowing SYSTEM-level code execution.
Other Critical vulnerabilities include CVE-2026-21536 (Devices Pricing Program RCE, CVSS 9.8), CVE-2026-26125 (Payment Orchestrator EoP, CVSS 8.6), CVE-2026-23651 and CVE-2026-26124 (Azure Container Instances Confidential Containers EoP, CVSS 6.7), and CVE-2026-26122 (ACI Confidential Containers Information Disclosure, CVSS 6.5).
---
**Revalidated on 2026-03-12**
One day after initial disclosure, CVE-2026-26110 and CVE-2026-26113 remain unpatched in many environments and have not yet been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No confirmed active exploitation in the wild has been observed as of March 12, 2026. However, the Zero Day Initiative has warned that exploitation 'could happen soon', noting these Preview Pane RCE bugs continue a concerning trend across recent Patch Tuesdays.
Cisco Talos has released Snort
Weaknesses (CWE)
CWE-843, CWE-822, CWE-79, CWE-284, CWE-125, CWE-416, CWE-269
Target sectors: government, financial, healthcare, technology, education, defense, energy, manufacturing, retail, legal
Target regions: Global
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-26110, CVE-2026-26113, CVE-2026-26144, CVE-2026-21262, CVE-2026-26127, CVE-2026-23668, CVE-2026-24289, CVE-2026-24291, CVE-2026-24294, CVE-2026-25187, T1566, T1190, T1204, T1203, T1068, T1211, T1027, T1212, T1005, T1114