Microsoft March 2026 Patch Tuesday Fixes 77+ Flaws, Highlights AI‑Driven Discovery
Microsoft released March 2026 Patch Tuesday with fixes for at least 77 vulnerabilities across Windows and related software; there are no new zero-days, but several high-severity flaws require attention, including CVE-2026-21262 (SQL Server privilege escalation), CVE-2026-26127 (.NET denial of service), and Office remote-code-execution flaws via the Preview Pane (CVE-2026-26113/26110). Additional privilege-escalation CVEs affect Windows components (CVE-2026-24291/24294/24289/25187). An AI-discovered CVE-2026-21536 in the Microsoft Devices Pricing Program is noted as an example of AI-driven vulnerability research. Microsoft also issued an out-of-band patch for Windows Server 2022 to fix a Windows Hello for Business certificate renewal issue; Adobe and Mozilla separately released updates for their products. For full details, see the SANS ISC Patch Tuesday post.
- Microsoft Patch Tuesday, March 2026 Edition Krebs on Security
- Microsoft Patches 83 Vulnerabilities SecurityWeek
- Microsoft Patches 83 CVEs in March Update Dark Reading | Security
- Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack theregister.com
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days The Hacker News
Reading Insights
0
4
3 min
vs 4 min read
82%
642 → 113 words
Want the full story? Read the original article
Read on Krebs on Security