Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityproof-of-concept-release

Microsoft March Patch Tuesday Ships 83 Fixes and Windows 11 Cumulative Updates

Updated 3mo agoFirst seen Mar 10, 202618 sources

Microsoft’s March Patch Tuesday security release shipped fixes for 83 vulnerabilities across its enterprise software and services, and was notable for having no actively exploited zero-days for the first time in six months. Microsoft flagged six vulnerabilities as “more likely to be exploited,” and noted two issues—CVE-2026-21262 and CVE-2026-26127—were publicly known at release. Researchers highlighted an Excel information-disclosure issue, CVE-2026-26144, describing a scenario where an attacker could potentially induce a Copilot Agent to exfiltrate data in a zero-click style workflow, and also pointed to Office flaws CVE-2026-26110 and CVE-2026-26113 (CVSS 8.4) that could enable arbitrary code execution via the Office preview pane.

Microsoft also released mandatory Windows 11 cumulative updates KB5079473 (25H2/24H2) and KB5078883 (23H2) that incorporate the March 2026 Patch Tuesday security fixes, along with additional non-security changes. The updates advance build numbers to 26200.8037/26100.8037 (25H2/24H2) and 22631.6783 (23H2), expand “high-confidence device targeting” to increase coverage for automatic delivery of new Secure Boot certificates, and include reliability improvements such as better File Explorer search across drives and changes to Windows Defender Application Control (WDAC) behavior for COM objects (policy listing support).

Share:
Microsoft March Patch Tuesday Ships 83 Fixes and Windows 11 Cumulative Updates
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 11, 20263mo ago

JPCERT/CC issues advisory on Microsoft March 2026 updates

On 2026-03-11, JPCERT/CC published advisory JPCERT-AT-2026-0005 warning that vulnerabilities fixed in Microsoft's March 2026 updates could allow remote code execution. It urged organizations to review Microsoft's guidance and apply the relevant updates through Microsoft Update, Windows Update, or the Update Catalog.

Mar 10, 20264mo ago

Microsoft announces Autopatch hotpatching will become default in May 2026

In connection with the March 2026 Patch Tuesday cycle, Microsoft said Windows Autopatch defaults would change to enable hotpatch security updates for eligible devices starting with the May 2026 Windows security update. This signaled an upcoming change in how some enterprise systems will receive security fixes.

Microsoft releases Windows 11 March 2026 cumulative updates

On 2026-03-10, Microsoft released mandatory Windows 11 cumulative updates KB5079473 for versions 25H2/24H2 and KB5078883 for version 23H2. The updates addressed security issues and bugs, expanded Secure Boot certificate targeting, and added features including built-in Sysmon as an optional native Windows feature.

Microsoft says Devices Pricing Program RCE was already mitigated

Microsoft included CVE-2026-21536, a critical remote code execution flaw in the Microsoft Devices Pricing Program, in the March 2026 disclosures and stated the issue had already been fully mitigated server-side. Multiple reports noted that no customer action was required for this specific vulnerability.

Microsoft patches critical Office and Excel flaws with preview-pane and Copilot risk

Microsoft fixed critical Office remote code execution vulnerabilities CVE-2026-26110 and CVE-2026-26113, which can be triggered through the Office Preview Pane, as well as Excel information disclosure flaw CVE-2026-26144. Researchers noted the Excel issue could enable zero-click style data exfiltration through Microsoft 365 Copilot Agent mode.

Microsoft fixes two publicly disclosed vulnerabilities in SQL Server and .NET

The March 2026 release patched CVE-2026-21262, a SQL Server privilege-escalation flaw that could let an authorized user gain sysadmin privileges, and CVE-2026-26127, a .NET denial-of-service bug. Both issues were publicly known before patches were released, but Microsoft reported no evidence of in-the-wild exploitation.

Microsoft releases March 2026 Patch Tuesday security updates

On 2026-03-10, Microsoft issued its March 2026 Patch Tuesday updates, fixing roughly 79-84 vulnerabilities across Windows, Office, SQL Server, Azure, .NET, Edge, and other products. Microsoft said none of the addressed flaws were known to be actively exploited at release time, though two had been publicly disclosed.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

96 LINKEDOpen in app
Vulnerabilities
35 linked
SQL Server Elevation of Privilege VulnerabilityType Confusion RCE in Microsoft Office.NET out-of-bounds read denial of serviceMicrosoft Office Preview Pane Remote Code Execution via Untrusted Pointer DereferenceMicrosoft Excel Copilot Agent Information Disclosure via XSSWindows Kernel NDIS Driver Use-After-Free Local Privilege EscalationWindows SMB Server Elevation of Privilege via Improper AuthenticationWinlogon Elevation of Privilege VulnerabilityLocal Privilege Escalation in Microsoft Windows Graphics ComponentRegPwnWindows Kernel Use-After-Free Elevation of PrivilegeRemote Code Execution in Microsoft Devices Pricing ProgramSSRF Elevation of Privilege in Azure MCP Server ToolsWindows Print Spooler Use-After-Free Remote Code ExecutionRemote Code Execution in Microsoft SharePoint ServerRemote Code Execution in Microsoft Office SharePoint via Deserialization of Untrusted DataLocal Code Execution in Microsoft Office ExcelWindows SMB Server Elevation of Privilege via Kerberos ReflectionAzure Entra ID Elevation of Privilege via External Initialization of Trusted Variables or Data StoresElevation of Privilege in Azure Compute Gallery via Permissive Regular ExpressionPrivilege Escalation in Azure Compute Gallery path handlingPayment Orchestrator Service Elevation of Privilege VulnerabilityPrivilege Escalation in Active Directory Domain ServicesWindows Kernel Elevation of Privilege via External Control of File Name or PathImproper Authentication Elevation of Privilege in Azure ArcRemote Code Execution via Vulnerable Third-Party PyPI Dependency in zero-shot-scfoundationCross-Site Scripting Spoofing in Microsoft Office SharePointWindows Ancillary Function Driver for WinSock Elevation of PrivilegeAuthentication Bypass in Azure Windows Virtual Machine AgentWindows Telephony Service Heap-Based Buffer Overflow Privilege EscalationSQL Injection Privilege Escalation in Microsoft SQL ServerSQL Server Elevation of Privilege Vulnerability in Input Type ValidationUntrusted Search Path RCE in Windows GDIOut-of-bounds Read in Windows GDI+ Bitmap ParsingDeep Link Hijacking in Microsoft Authenticator
Affected products
32 linked
Microsoft OfficeNetWindows 11Windows Smb ServerMicrosoft 365 CopilotPayment Orchestrator ServiceWindows Print SpoolerOffice 2019Windows ServerSharepoint Server 2019Windows 10Office 2016Azure Connected Machine AgentWindows Server 2022Azure Compute GallerySharepoint Enterprise Server 2016Adobe CommerceMicrosoft Entra IdSnortChromiumWindows KernelWindows File ExplorerWindows Ancillary Function Driver For WinsockWindows Routing And Remote Access Service (Rras)Microsoft Graphics ComponentAzure Iot ExplorerMicrosoft Aci Confidential ContainersWindows Graphics ComponentSnortActive Directory Domain ServicesMicrosoft AuthenticatorAzure Mcp Server Tools
Organizations
29 linked
Microsoft CorporationTenableImmersiveTrend MicroRapid7Action1GoogleAutomoxMozillaSalesforceCohesityCisco SystemsBleepingComputerXBOWHackerOneSOCRadarSANS InstituteSecurityWeekOutpost24GitHubAdobeFortraThe Cyber ExpressKrebsOnSecurityAskWoodySecurity AffairsPCWorldTrendAI Zero Day InitiativeProject Overwatch
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft March Patch Tuesday Ships 83 Fixes and Windows 11 Cumulative Updates | Mallory