CVE-2026-26144
CVSS 7.5 HIGH: improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows… Microsoft patch: Click to Run.
Vulnerabilities & Exploits · Web App Attack
A routine Excel XSS now matters because Copilot Agent mode turns script execution into autonomous data theft. The standard XSS response misses the real break: the payload does not need to steal a cookie or trigger a visible redirect when the AI agent can read the workbook and send its contents out on its own.
Microsoft patched CVE-2026-26144 on March 10, 2026. The flaw affects Excel and chains with Copilot Agent mode, letting a malicious spreadsheet fire without a click and exfiltrate spreadsheet data to an attacker-controlled endpoint with no user prompt or visual warning.
The risk is broader than this one bug. Any application that lets an AI agent act inside the user context can turn old web flaws into silent, automated leakage paths, so traditional severity labels will keep understating impact.
1 source · Apr 17
CVSS 7.5 HIGH: improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows… Microsoft patch: Click to Run.
Dark Reading
Every Old Vulnerability Is Now an AI Vulnerability
AI's danger isn't that it's creating new bugs, it's that it's amplifying old ones.
originalPart of the PlainSec briefing for 2026-04-18
Every edition of this story: Excel XSS Becomes Silent Data Exfiltration Path