Microsoft’s March 2026 Patch Tuesday shipped fixes for 79 vulnerabilities, including two zero-day flaws. Public reporting and third-party patch reviews highlight a mix of Important and Critical issues across Microsoft’s ecosystem, including .NET (CVE-2026-26127 DoS; CVE-2026-26131 EoP), Active Directory Domain Services (CVE-2026-25177 EoP), ASP.NET Core (CVE-2026-26130 DoS), and multiple Azure components such as ACI Confidential Containers (CVE-2026-23651, CVE-2026-26124 EoP; CVE-2026-26122 information disclosure) and Azure IoT Explorer (CVE-2026-26121 spoofing; CVE-2026-23661/23662/23664 information disclosure).
Independent analysis (ZDI and SANS ISC) corroborated the breadth of affected products and provided additional scoring/metadata, including CVSS ratings and exploitability flags. ZDI’s review also called out additional Critical items in the release such as Microsoft Office RCE (CVE-2026-26110, CVE-2026-26113) and other high-impact vulnerabilities, while SANS ISC’s Patch Tuesday coverage additionally noted bundled Chromium-tracked fixes (multiple CVE-2026-3536 through CVE-2026-3544 entries) that commonly map to Microsoft’s browser/embedded Chromium components. Organizations should prioritize patching systems exposed to untrusted content or authentication boundaries (e.g., Office, AD DS, Azure agents/extensions) and validate deployment coverage across both Windows and cloud-connected workloads.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Patch Tuesday coverage noted that SQL Server 2012 Parallel Data Warehouse would reach the end of extended support on March 31, 2026. This was highlighted as an important lifecycle milestone for organizations still running the product.
The March 2026 Patch Tuesday set also included notable high-severity vulnerabilities such as CVE-2026-21536 in Microsoft Devices Pricing Program and CVE-2026-26030 in Microsoft Semantic Kernel InMemoryVectorStore, along with multiple SharePoint, Office, Excel, RRAS, and Windows privilege-escalation flaws. These issues were identified as among the most severe bugs in the month's release.
Researchers highlighted CVE-2026-26123, an Important Microsoft Authenticator vulnerability on iOS and Android that could let a malicious app impersonate the legitimate Authenticator app by abusing a custom URL scheme handler. Commentary noted exploitation may require less user interaction than Microsoft's guidance suggested.
Security coverage of the March 2026 updates singled out CVE-2026-21262, a SQL Server elevation-of-privilege vulnerability that could allow an authorized attacker to gain sysadmin privileges over the network on supported SQL Server versions. Analysts emphasized the risk posed by internet-exposed SQL Server deployments.
The March 2026 release identified two publicly disclosed vulnerabilities: CVE-2026-21262 in SQL Server and CVE-2026-26127 in .NET. Multiple sources noted these were publicly disclosed at release time, while most reporting said there was no evidence of active exploitation.
On March 10, 2026, Microsoft released its March Patch Tuesday security updates covering roughly 77-79 vulnerabilities across Windows, Office, Azure, SQL Server, SharePoint, .NET, Edge, and related products. The release included a mix of Critical and Important flaws spanning remote code execution, elevation of privilege, denial of service, information disclosure, spoofing, and security feature bypass.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
lansweeper.com
Open sourcethezdi.com
Open sourceisc.sans.edu
Open sourcebleepingcomputer.com
Open sourcezerodayinitiative.com
Open sourceisc.sans.edu
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.