ยท 4 min read ยท Edition #25

3 Critical Office RCEs + Copilot Wave 3: What to Know Now

March Patch Tuesday drops 83 vulnerabilities including three critical Office RCE flaws โ€” one of which weaponizes Copilot Agent Mode for zero-click data exfiltration. Meanwhile, Copilot Wave 3 is here with a new E7 tier at $99/user and Secure Boot deadlines are approaching.

๐Ÿ“‹ TL;DR โ€” What You Need to Know

๐Ÿ”ด Patch Tuesday: 3 Office RCE Vulnerabilities Require Immediate Action

Microsoft's March 2026 security update addresses 83 total vulnerabilities, but three deserve your urgent attention:

CVE CVSS Impact
CVE-2026-26110 8.4 Office RCE via type confusion โ€” preview pane is attack vector
CVE-2026-26113 8.4 Office RCE via untrusted pointer dereference
CVE-2026-26144 7.5 Excel XSS that exfiltrates data via Copilot Agent Mode โ€” zero-click
โš ๏ธ CVE-2026-26144 is particularly concerning: An attacker can craft a malicious Excel file that, when processed by Copilot Agent Mode, triggers data exfiltration over the network without user interaction.

Affected systems: M365 Apps for Enterprise, SharePoint Server 2016/2019/SE

๐ŸŸก Copilot Wave 3 & Copilot Cowork Launch

Microsoft rolled out Wave 3 of M365 Copilot on March 9, introducing a significant leap in AI capabilities:

Teams Rooms Features Expand to Government Clouds

Good news for GCC, GCC High, and DoD customers โ€” key Teams Rooms capabilities are arriving:

Secure Boot Certificate Deadline: June 2026

Organizations must apply February + March 2026 cumulative updates to Windows endpoints before the June deadline. This isn't optional โ€” devices without the updated certificates will have boot issues after the cutoff.

โšก Quick Hits

โœ… Admin Action Items

Priority Action Deadline
๐Ÿ”ด Critical Deploy March security updates for M365 Apps ASAP
๐Ÿ”ด Critical Patch SharePoint Server 2016/2019/SE ASAP
๐ŸŸก High Plan Secure Boot certificate update deployment Before June 2026
๐ŸŸก High Review Copilot Wave 3 features & E7 licensing options This quarter
๐Ÿ”ต Normal Update Teams Rooms in GCC environments Per change management

๐Ÿ”ฅ The Bottom Line

Another week, another batch of critical patches โ€” such is the rhythm of M365 administration. The CVE-2026-26144 vulnerability is a stark reminder that as AI capabilities expand, so do attack surfaces. Copilot Agent Mode is powerful, but that power needs to be secured.

On the brighter side, Wave 3 represents a genuine step-change in how AI integrates with productivity tools. If your organization is still on the fence about Copilot, the new E7 tier might be the push you need โ€” or at least a conversation worth having with finance.

Stay ahead. Stay informed. ๐Ÿ”ฅ

Questions about patching or Copilot licensing?

Fireside Cloud Solutions helps organizations navigate security updates and AI adoption. Let's talk about your roadmap.

Schedule a Free Consultation โ†’
Patch Tuesday Security CVE RCE Copilot Wave 3 Cowork E7 Teams Rooms Secure Boot Microsoft 365
FS
Fireside Cloud Solutions
Microsoft 365 & Power Platform Consulting ยท firesidecloudsolutions.com
Sources: Microsoft Security Response Center, Microsoft 365 Admin Center, M365 Roadmap, Microsoft Official Blog
The M365 Pulse is published weekly by Fireside Cloud Solutions. Next edition: March 24, 2026.