Microsoft Patch Tuesday March 2026: 79 Flaws Fixed, Two Public Zero-Days

TL;DR Summary
Microsoft's March 2026 Patch Tuesday closes 79 vulnerabilities, including two publicly disclosed zero-days: a SQL Server elevation-of-privilege flaw (CVE-2026-21262) and a .NET denial-of-service flaw (CVE-2026-26127). The update also patches two Office remote-code-execution flaws via the Preview Pane (CVE-2026-26110, CVE-2026-26113) and an Excel information-disclosure flaw potentially exposing Copilot data (CVE-2026-26144). Fixes span Windows, Edge, Azure, and more, with several critical bugs; users should update promptly.
- Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws BleepingComputer
- Microsoft Patch Tuesday, March 2026 Edition Krebs on Security
- Microsoft Patches 83 Vulnerabilities SecurityWeek
- The March 2026 Security Update Review Zero Day Initiative
- Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack theregister.com
Reading Insights
Total Reads
0
Unique Readers
2
Time Saved
11 min
vs 12 min read
Condensed
97%
2,357 → 64 words
Want the full story? Read the original article
Read on BleepingComputer