Microsoft has published an advisory for CVE-2026-23674 — a MapUrlToZone security feature bypass in Windows — and the March 2026 updates include a patch that addresses an improper resolution of path equivalence in the MapUrlToZone API that can allow remote resources to be incorrectly classified...
Microsoft has logged CVE-2026-20949 as a Security Feature Bypass affecting Microsoft Excel, and the entry in the Microsoft Security Response Center’s Update Guide highlights a constrained public description and an explicit report‑confidence signal that security teams must interpret when triaging...