Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilitycloud-service-vulnerabilityidentity-authentication-vulnerability

Microsoft March 2026 Patch Tuesday Fixes Two Zero-Days and Dozens of Vulnerabilities

Updated 3mo agoFirst seen Mar 10, 20267 sources

Microsoft’s March 2026 Patch Tuesday shipped fixes for 79 vulnerabilities, including two zero-day flaws. Public reporting and third-party patch reviews highlight a mix of Important and Critical issues across Microsoft’s ecosystem, including .NET (CVE-2026-26127 DoS; CVE-2026-26131 EoP), Active Directory Domain Services (CVE-2026-25177 EoP), ASP.NET Core (CVE-2026-26130 DoS), and multiple Azure components such as ACI Confidential Containers (CVE-2026-23651, CVE-2026-26124 EoP; CVE-2026-26122 information disclosure) and Azure IoT Explorer (CVE-2026-26121 spoofing; CVE-2026-23661/23662/23664 information disclosure).

Independent analysis (ZDI and SANS ISC) corroborated the breadth of affected products and provided additional scoring/metadata, including CVSS ratings and exploitability flags. ZDI’s review also called out additional Critical items in the release such as Microsoft Office RCE (CVE-2026-26110, CVE-2026-26113) and other high-impact vulnerabilities, while SANS ISC’s Patch Tuesday coverage additionally noted bundled Chromium-tracked fixes (multiple CVE-2026-3536 through CVE-2026-3544 entries) that commonly map to Microsoft’s browser/embedded Chromium components. Organizations should prioritize patching systems exposed to untrusted content or authentication boundaries (e.g., Office, AD DS, Azure agents/extensions) and validate deployment coverage across both Windows and cloud-connected workloads.

Share:
Microsoft March 2026 Patch Tuesday Fixes Two Zero-Days and Dozens of Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 31, 20263mo ago

SQL Server 2012 Parallel Data Warehouse support end date noted

Patch Tuesday coverage noted that SQL Server 2012 Parallel Data Warehouse would reach the end of extended support on March 31, 2026. This was highlighted as an important lifecycle milestone for organizations still running the product.

Mar 10, 20264mo ago

March 2026 updates include several high-severity critical issues

The March 2026 Patch Tuesday set also included notable high-severity vulnerabilities such as CVE-2026-21536 in Microsoft Devices Pricing Program and CVE-2026-26030 in Microsoft Semantic Kernel InMemoryVectorStore, along with multiple SharePoint, Office, Excel, RRAS, and Windows privilege-escalation flaws. These issues were identified as among the most severe bugs in the month's release.

Microsoft Authenticator mobile app flaw draws attention

Researchers highlighted CVE-2026-26123, an Important Microsoft Authenticator vulnerability on iOS and Android that could let a malicious app impersonate the legitimate Authenticator app by abusing a custom URL scheme handler. Commentary noted exploitation may require less user interaction than Microsoft's guidance suggested.

Researchers highlight SQL Server flaw CVE-2026-21262 as a major risk

Security coverage of the March 2026 updates singled out CVE-2026-21262, a SQL Server elevation-of-privilege vulnerability that could allow an authorized attacker to gain sysadmin privileges over the network on supported SQL Server versions. Analysts emphasized the risk posed by internet-exposed SQL Server deployments.

Microsoft discloses two publicly known flaws in March 2026 updates

The March 2026 release identified two publicly disclosed vulnerabilities: CVE-2026-21262 in SQL Server and CVE-2026-26127 in .NET. Multiple sources noted these were publicly disclosed at release time, while most reporting said there was no evidence of active exploitation.

Microsoft releases March 2026 Patch Tuesday updates

On March 10, 2026, Microsoft released its March Patch Tuesday security updates covering roughly 77-79 vulnerabilities across Windows, Office, Azure, SQL Server, SharePoint, .NET, Edge, and related products. The release included a mix of Critical and Important flaws spanning remote code execution, elevation of privilege, denial of service, information disclosure, spoofing, and security feature bypass.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

45 LINKEDOpen in app
Affected products
42 linked
NetAzure Connected Machine AgentAsp.Net CoreChromiumWindows KernelWindows Hyper-VWindows NtfsWindows Smb ServerWindows KerberosWindows Telephony ServiceMicrosoft OfficeWindows Ancillary Function Driver For WinsockWindows Routing And Remote Access Service (Rras)Windows Connected Devices Platform ServiceAzure Iot ExplorerWindows Graphics ComponentWindows Dwm Core LibraryActive Directory Domain ServicesWindows Print SpoolerWindows Projected File SystemMicrosoft AuthenticatorWindows Universal Disk Format File System Driver (Udfs)Azure Mcp Server ToolsLinux Azure Diagnostic Extension (Lad)Windows Shell Link ProcessingWindows Device Association ServiceWindows Accessibility Infrastructure (Atbroker.Exe)Windows Mobile Broadband DriverWindows App InstallerAzure Ad Ssh Login Extension For LinuxSql ServerSharepoint ServerSystem Center Operations ManagerExcelOfficeSemantic KernelAzure Container Instances (Aci) Confidential ContainersDevices Pricing ProgramAci Confidential ContainersPayment Orchestrator ServiceWindows System Image ManagerBroadcast Dvr
Organizations
3 linked
Microsoft CorporationGitHubGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.