A routine Excel XSS now matters because Copilot Agent mode turns script execution into autonomous data theft. The standard XSS response misses the real break: the payload does not need to steal a cookie or trigger a visible redirect when the AI agent can read the workbook and send its contents out on its own.
Microsoft patched CVE-2026-26144 on March 10, 2026. The flaw affects Excel and chains with Copilot Agent mode, letting a malicious spreadsheet fire without a click and exfiltrate spreadsheet data to an attacker-controlled endpoint with no user prompt or visual warning.
The risk is broader than this one bug. Any application that lets an AI agent act inside the user context can turn old web flaws into silent, automated leakage paths, so traditional severity labels will keep understating impact.