Microsoft Released March 2026 Software Updates

Microsoft has released software updates as part of its March 2026 Patch Tuesday. The updates fix 79 security vulnerabilities in total, including 2 publicly disclosed zero-day vulnerabilities.

The breakdown of the vulnerabilities are as follows:

  • 46 privilege escalation

  • 2 security feature bypass

  • 18 remote code execution

  • 10 information disclosure

  • 4 denial of service

  • 4 spoofing

The publicly disclosed zero-days are as follows:

  • CVE-2026-21262 - vulnerability in SQL Server that can lead to elevation of privilege

  • CVE-2026-26127 - vulnerability in .NET that can lead to denial of service

Why You Should Care?

Zero-day vulnerabilities are vulnerabilities where a flaw has been identified but there was no fix for the flaw, which means attackers will try to exploit as many targets as possible before users fix the vulnerability. This makes it extra dangerous, and needs to be addressed as soon as possible.

In this case, two zero-day vulnerabilities are publicly disclosed, which means attackers will likely rush to write exploit code and start attacking businesses. It is only a matter of time before the attackers compromise your business. Now that patches are available, it is critical to apply the patches as soon as possible to avoid getting compromised.

What Should You Do?

  • Test the patches ASAP at your organization, and make sure it does not break any business applications

  • Prioritize patching the zero-day vulnerabilities

  • Roll out the rest of the Patch Tuesday updates

References

  • https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/

Next
Next

FBI breached and more - Mar 8, 2026