CVE-2026-26144: Microsoft 365 Apps

Medium severity, CVSS 4.7. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Affected products

  • Microsoft 365 Apps: affected versions not specified

Published 2026-03-10. Last modified 2026-06-17.