Skip to content

CVE-2026-26118

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
March 10, 2026
Last Seen
July 29, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

On March 10, 2026, Microsoft released its Patch Tuesday updates, fixing 79 vulnerabilities, including two zero-day flaws. The updates address critical vulnerabilities across various products, with one zero-day actively exploited in the wild, necessitating immediate attention from security teams.

Recent research revealed that a significant number of Model Context Protocol (MCP) servers are exposed to the Internet without proper authentication, affecting many organizations, including Fortune 500 companies. Wiz found that 1 in 6 cloud environments expose at least one MCP server, with 70% retur...

Microsoft Office Excel has multiple vulnerabilities that allow unauthorized attackers to execute code locally. These include an out-of-bounds read, use after free, untrusted pointer dereference, heap-based buffer overflow, and type confusion. A cross-site scripting vulnerability also allows informat...

Public Exploits

Checking GitHub for proof-of-concept code…