Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryinitial-access-method

Microsoft Patch Tuesday Fixes Critical Office Preview Pane RCE Flaws

Updated 3mo agoFirst seen Mar 12, 20262 sources

Microsoft released March Patch Tuesday security updates addressing nearly 80 vulnerabilities, including critical Microsoft Office remote code execution issues that can be triggered via the Windows Preview Pane. TechRepublic highlighted two Office flaws—CVE-2026-26113 and CVE-2026-26110—where simply previewing a malicious document can lead to attacker-controlled code execution, creating a low-friction initial access path for enterprise endpoints.

Cybersecurity News provided additional technical detail on CVE-2026-26110, describing it as a type confusion bug (CWE-843) with a CVSS 8.4 rating affecting Office across Windows, macOS, and Android. The write-up notes that while Microsoft labels it “remote code execution,” exploitation requires the payload to execute on the local machine (i.e., attacker code runs locally after the victim triggers the vulnerable processing), and emphasizes the risk that Preview Pane handling can enable compromise without the user opening the document in the traditional sense.

Share:
Microsoft Patch Tuesday Fixes Critical Office Preview Pane RCE Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 10, 20264mo ago

Microsoft discloses Excel flaw that could leak Copilot Agent data

Microsoft's March Patch Tuesday release included CVE-2026-26144, an Excel information disclosure vulnerability that could cause Copilot Agent mode to expose sensitive data across a network. The issue was included among the March 10 security fixes.

Microsoft patches AI-discovered Devices Pricing Program vulnerability

Microsoft fixed CVE-2026-21536, a CVSS 9.8 vulnerability affecting the Microsoft Devices Pricing Program. The flaw was reportedly discovered by an autonomous AI agent named XBOW.

Microsoft addresses publicly disclosed SQL Server and .NET flaws

The March 2026 updates also remediated two publicly disclosed vulnerabilities: SQL Server privilege escalation CVE-2026-21262 and .NET denial-of-service issue CVE-2026-26127. Their prior public disclosure increased urgency because technical details may already have been available.

Microsoft patches critical Office Preview Pane RCE vulnerabilities

Microsoft fixed high-priority Office remote code execution flaws CVE-2026-26110 and CVE-2026-26113, which can be triggered through the Windows File Explorer Preview Pane by viewing a malicious document. Microsoft advised immediate patching and suggested disabling the Preview Pane as a temporary mitigation if updates cannot be applied right away.

Microsoft releases March Patch Tuesday fixes for 78 vulnerabilities

On March 10, 2026, Microsoft issued security updates covering 78 vulnerabilities across products including Office, Excel, SQL Server, .NET, and the Microsoft Devices Pricing Program. The release included three critical issues and no actively exploited zero-days.

Anonymous researcher discloses Office RCE flaw CVE-2026-26110 to Microsoft

An anonymous researcher reported CVE-2026-26110, a type confusion vulnerability in Microsoft Office that can lead to arbitrary code execution. Microsoft said there was no known in-the-wild exploitation or proven exploit code at the time of disclosure.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.