Microsoft released its March 2026 Patch Tuesday security updates addressing vulnerabilities across a broad set of products, and the Canadian Centre for Cyber Security issued advisory AV26-213 urging organizations to review Microsoft’s guidance and apply the required patches. The advisory highlights updates spanning Windows (10/11 and multiple Windows Server versions), .NET/ASP.NET Core, Microsoft 365, Office/Excel, SharePoint, SQL Server, and multiple Azure-related components and extensions (including Azure Arc/Connected Machine Agent and other Windows/Linux extensions), reflecting a wide attack surface for enterprise environments.
Arctic Wolf’s Patch Tuesday coverage calls out specific fixes affecting Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016, including CVE-2026-26113, and also notes Office-family updates addressing CVE-2026-26110 and CVE-2026-26113 across Office 2016/2019, Office LTSC 2021/2024 (including Mac), and Office for Android, with referenced KB updates (e.g., 5002843, 5002845, 5002847, 5002850, 5002851, 5002838). Together, the sources indicate that organizations running SharePoint and Office (including Click-to-Run deployments) should prioritize patch validation and deployment using Microsoft’s Security Update Guide and the March 2026 security update listings referenced by the Cyber Centre.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
By 2026-03-11, additional reporting identified specific products affected by March 2026 Patch Tuesday vulnerabilities, notably CVE-2026-26113, CVE-2026-26110, and CVE-2026-26144. The reporting mapped SharePoint Server, multiple Microsoft Office editions, and Microsoft 365 Apps for Enterprise to corresponding KBs, Click-to-Run updates, and release notes.
On 2026-03-10, Microsoft published its March 2026 monthly security advisories covering vulnerabilities across multiple products and services, including Windows, .NET/ASP.NET Core, Office, SharePoint, SQL Server, and Azure components. The advisories directed users and administrators to review the Security Update Guide and apply the relevant patches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.