Microsoft Addresses 83 Vulnerabilities, Including Two Zero-Days, in March 2026 Patch Tuesday
Microsoft released its March 2026 Patch Tuesday security updates on March 10, 2026, addressing a total of 83 Common Vulnerabilities and Exposures (CVEs). This includes two publicly disclosed zero-day vulnerabilities, marking a significant security update for Windows, Microsoft Office, Azure, SQL Server, and .NET.
Key Highlights of the March 2026 Patch Tuesday
- Total Vulnerabilities Addressed: 83 CVEs
- Zero-Day Vulnerabilities: 2 publicly disclosed
- Critical Vulnerabilities: 8
- Important Vulnerabilities: 75
Zero-Day Vulnerabilities
The two zero-day vulnerabilities addressed in this patch cycle were publicly known before a fix was available. Microsoft classifies these as publicly disclosed zero-days, even if they aren’t actively exploited. The vulnerabilities include:
- CVE-2026-21262: A SQL Server elevation of privilege vulnerability allowing attackers to gain SQLAdmin privileges through improper access control. [BleepingComputer]
- CVE-2026-26127: [Tenable]
Vulnerability Breakdown
The 83 vulnerabilities addressed cover a wide range of Microsoft products and services, including:
- .NET
- ASP.NET Core
- Active Directory Domain Services
- Azure Arc
- Azure Compute Gallery
- Azure Entra ID
- Azure IoT Explorer
- Azure Linux Virtual Machines
- Azure MCP Server
- Azure Portal
- Windows Admin Center
- Azure Windows Virtual Machine Agent
- Broadcast DVR
- Connected Devices Platform Service (Cdpsvc)
- Microsoft Authenticator
- Microsoft Brokering File System
- Microsoft Graphics Component
- Microsoft Office
- Microsoft Office Excel
- Microsoft Office SharePoint
- Payment Orchestrator Service
- Push Message Routing Service
- Role: Windows Hyper-V
- SQL Server
- System Center Operations Manager
- Windows Accessibility Infrastructure (ATBroker.exe)
- Windows Ancillary Function Driver for WinSock
- Windows App Installer
- Windows Authentication Methods
- Windows Bluetooth RFCOM Protocol Driver
- Windows DWM Core Library
- Windows Device Association Service
- Windows Extensible File Allocation
- Windows File Server
- Windows GDI
- Windows GDI+
- Windows Kerberos
- Windows Kernel
- Windows MapUrlToZone
- Windows Mobile Broadband
- Windows NTFS
- Windows Performance Counters
- Windows Print Spooler Components
- Windows Projected File System
- Windows Resilient File System (ReFS)
- Windows Routing and Remote Access Service (RRAS)
- Windows SMB Server
- Windows Shell Link Processing
- Windows System Image Manager
- Windows Telephony Service
- Windows Universal Disk Format File System Driver (UDFS)
- Windows Win32K
- Winlogon
A significant number of the vulnerabilities (55) are related to elevation of privilege, even as others cover areas like remote code execution (18), information disclosure (10), and denial of service (4). [Tenable]
What This Means for Users
Microsoft strongly recommends that users and administrators apply these updates as soon as possible to mitigate potential security risks. While there is currently no evidence of active exploitation for the zero-day vulnerabilities, the publicly disclosed nature of these flaws increases the risk of future attacks. [CyberScoop]
This Patch Tuesday marks the first in six months without any actively exploited zero-day vulnerabilities, indicating a proactive approach to security by Microsoft. [CyberScoop]
Keep reading