Early March 2026 Vendor Security Advisories and Patch Releases Across Enterprise, Mobile, and ICS Products
Multiple vendors issued security advisories and patch releases in late February and early March 2026, prompting coordinated update guidance from national and regional CERTs. The Canadian Centre for Cyber Security highlighted updates for Django (fixed in 4.2.29, 5.2.12, 6.0.3), Samsung mobile devices (March 2026 security update), Qualcomm (March 2026 monthly bulletin), Veeam Kasten for Kubernetes / Kasten K10, VMware Tanzu components (including Greenplum and RabbitMQ on Kubernetes), and Red Hat advisories including Linux kernel updates across multiple RHEL-related platforms.
Industrial and infrastructure-facing products were also covered via CISA ICS advisories spanning a broad set of vendors and solutions (including EV charging ecosystems, building management, cameras, and DCS/SCADA platforms such as Schneider Electric EcoStruxure Building Operation Workstation and Yokogawa CENTUM VP), with guidance to apply mitigations and updates where available. Additional enterprise patch guidance included Dell advisories affecting PowerStore T and PowerEdge server lines (including AMD-based models and NVIDIA networking/DOCA-related components), and IBM advisories across a wide portfolio (including App Connect Enterprise, CICS TX, License Metric Tool, Maximo, Sterling Secure Proxy, Terracotta, QRadar, and others). HKCERT separately summarized Samsung vulnerabilities impacting Android devices and Exynos chipsets, listing multiple CVEs (e.g., CVE-2024-31328 and numerous 2025-series CVEs) with potential impacts including RCE, EoP, information disclosure, and DoS.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
9 events from the most recent confirmed update back to the earliest known activity.
Django publishes security advisory for supported release lines
On 2026-03-03, Django published a security advisory covering vulnerabilities in supported release lines, including Django 4.2 before 4.2.29, Django 5.2 before 5.2.12, and Django 6.0 before 6.0.3. The advisory instructed users to review the notice and update to fixed versions.
Samsung publishes mobile device security update
On 2026-03-03, Samsung released a security update for mobile devices addressing multiple vulnerabilities affecting versions prior to SMR-MAR-2026. Users and administrators were directed to Samsung's security update information for remediation details.
Qualcomm publishes March 2026 security bulletin
On 2026-03-02, Qualcomm published its March 2026 security bulletin addressing vulnerabilities affecting Qualcomm products. The bulletin served as the primary source of remediation guidance referenced by subsequent advisories.
Veeam publishes Kasten for Kubernetes security advisory
On 2026-03-02, Veeam released a security advisory addressing vulnerabilities in multiple versions of Veeam Kasten for Kubernetes and Kasten K10 by Veeam. The vendor provided references to security fixes, improvements, and additional knowledge base details.
VMware releases Tanzu product security advisories
On 2026-02-27, VMware published security advisories for multiple Tanzu products, including Tanzu Greenplum, Greenplum Upgrade, Greenplum Backup and Restore, and Tanzu RabbitMQ on Kubernetes. The advisories identified fixed-version thresholds for several affected components.
Dell publishes multiple security advisories across product lines
Between 2026-02-23 and 2026-03-01, Dell released multiple advisories for vulnerabilities affecting products including PowerStore T Security, PowerEdge servers, and NVIDIA BlueField, ConnectX, and DOCA-related components. The advisories specified affected versions and directed customers to apply updates.
CISA issues multiple ICS security advisories
Between 2026-02-23 and 2026-03-01, CISA published several ICS advisories covering vulnerabilities in products such as EV charging platforms, industrial control software, building management systems, and IP cameras. The advisories identified affected vendors and versions and recommended mitigations and updates where available.
IBM publishes multiple product security advisories
Between 2026-02-23 and 2026-03-01, IBM published multiple security advisories affecting a broad range of products, including data platforms, middleware, automation, identity governance, storage management, and security monitoring offerings. The advisories provided remediation guidance and updates for affected systems.
Red Hat publishes multiple product security advisories
Between 2026-02-23 and 2026-03-01, Red Hat released security advisories covering vulnerabilities across multiple products, including the Linux kernel, Red Hat Enterprise Linux, and related variants. Users were advised to review the advisories and apply the relevant updates.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
10 references tracked. Mallory keeps watching after this page renders.
Django security advisory (AV26-193) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceSamsung mobile security advisory (AV26-192) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceQualcomm security advisory - March 2026 monthly rollup (AV26-190) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceSamsung Products Multiple Vulnerabilities
hkcert.org
Open sourceRed Hat security advisory (AV26-184) - Canadian Centre for Cyber Security
cyber.gc.ca
Open source[Control systems] CISA ICS security advisories (AV26-183) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceDell security advisory (AV26-181) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceIBM security advisory (AV26-180) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


