Rewterz
DarkCrystal RAT aka DCRat – Active IOCs
March 13, 2026
Rewterz
Multiple Google Chrome Zero-Day Vulnerabilities Exploit in the Wild
March 13, 2026

Multiple Microsoft Office Excel Vulnerabilities

Severity

High

Analysis Summary

CVE-2026-26144 CVSS:7.5

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

CVE-2026-26107 CVSS:7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-26108 CVSS:7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-26109 CVSS:8.4

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-26112 CVSS:7.8

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Impact

  • Code Execution
  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2026-26144
  • CVE-2026-26107
  • CVE-2026-26108
  • CVE-2026-26109
  • CVE-2026-26112

Affected Vendors

  • Microsoft

Affected Products

  • Microsoft Office Online Server
  • Microsoft Office LTSC for Mac 2021
  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft Office 2019 for 32-bit editions
  • Microsoft Office 2019 for 64-bit editions
  • Microsoft Office LTSC 2021 for 32-bit editions
  • Microsoft Office LTSC 2021 for 64-bit editions
  • Microsoft Office LTSC 2024 for 64-bit editions
  • Microsoft Office LTSC 2024 for 32-bit editions
  • Microsoft Office LTSC for Mac 2024
  • Microsoft Excel 2016 (64-bit edition)
  • Microsoft Excel 2016 (32-bit edition)

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2026-26144

CVE-2026-26107

CVE-2026-26108

CVE-2026-26109

CVE-2026-26112