ai-security EN

Microsoft Patch Tuesday March 2026, (Tue, Mar 10th)

Microsoft Patch Tuesday March 2026

Published
2026-03-10. Last Updated
2026-03-10 17:33:47 UTC

by Johannes Ullrich (Version: 1)

0 comment(s)

Microsoft today released patches for 93 vulnerabilities, including 9 vulnerabilities in Chromium affecting Microsoft Edge. 8 of the vulnerabilities are rated critical. 2 were disclosed prior to today but have not yet been exploited. This update addresses no already-exploited vulnerabilities.

Disclose vulnerabilities:

CVE-2026-26127
A denial of service vulnerability in .Net. Microsoft considers exploitation unlikely. The issue arises from an out-of-bounds read and can be exploited across the network. No authentication is required.
CVE-2026-21262
A privilege escalation in SQL Server. An authenticated user may be able to escalate privileges to sysadmin.

Critical Vulnerabilities:

CVE-2026-21536
The vulnerability in Microsoft’s Devices Pricing Program allows remote code execution. But this product is only offered as a cloud service, and Microsoft has already deployed the patch. Microsoft credits the AI vulnerability scanning platform XBOW with discovering this vulnerability.
CVE-2026-26125
Similar to the above vulnerability, this elevation-of-privilege vulnerability in Microsoft’s Payment Orchestrator service has been mitigated by Microsoft.
CVE-2026-26113, CVE-2026-26110, CVE-2026-26144
These vulnerabilities affect Excel and Office.
CVE-2026-23651, CVE-2026-26124, CVE-2026-26122
These vulnerabilities affect Microsoft ACI Confidential Containers. No customer action is required. Microsoft already patched these issues.
Description
CVEDisclosedExploitedExploitability (old versions)current versionSeverityCVSS Base (AVG)CVSS Temporal (AVG)
.NET Denial of Service Vulnerability
CVE-2026-26127YesNo--Important7.56.5
.NET Elevation of Privilege Vulnerability
CVE-2026-26131NoNo--Important7.86.8
ASP.NET Core Denial of Service Vulnerability
CVE-2026-26130NoNo--Important7.56.5
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2026-25177NoNo--Important8.87.7
Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2026-26117NoNo--Important7.86.8
Azure IOT Explorer Spoofing Vulnerability
CVE-2026-26121NoNo--Important7.56.5
Azure IoT Explorer Information Disclosure Vulnerability
CVE-2026-23664NoNo--Important7.56.5
CVE-2026-23661NoNo--Important7.56.5
CVE-2026-23662NoNo--Important7.56.5
Azure MCP Server Tools Elevation of Privilege Vulnerability
CVE-2026-26118NoNo--Important8.87.7
Broadcast DVR Elevation of Privilege Vulnerability
CVE-2026-23667NoNo--Important7.06.1
Chromium: CVE-2026-3536 Integer overflow in ANGLE
CVE-2026-3536NoNo---
Chromium: CVE-2026-3538 Integer overflow in Skia
CVE-2026-3538NoNo---
Chromium: CVE-2026-3539 Object lifecycle issue in DevTools
CVE-2026-3539NoNo---
Chromium: CVE-2026-3540 Inappropriate implementation in WebAudio
CVE-2026-3540NoNo---
Chromium: CVE-2026-3541 Inappropriate implementation in CSS
CVE-2026-3541NoNo---
Chromium: CVE-2026-3542 Inappropriate implementation in WebAssembly
CVE-2026-3542NoNo---
Chromium: CVE-2026-3543 Inappropriate implementation in V8
CVE-2026-3543NoNo---
Chromium: CVE-2026-3544 Heap buffer overflow in WebCodecs
CVE-2026-3544NoNo---
Chromium: CVE-2026-3545 Insufficient data validation in Navigation
CVE-2026-3545NoNo---
GDI Remote Code Execution Vulnerability
CVE-2026-25190NoNo--Important7.86.8
GDI+ Information Disclosure Vulnerability
CVE-2026-25181NoNo--Important7.56.5
GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable
CVE-2026-26030NoNo--Important9.98.6
GitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability
CVE-2026-23654NoNo--Important8.87.7
Hybrid Worker Extension (Arc?enabled Windows VMs) Elevation of Privilege Vulnerability
CVE-2026-26141NoNo--Important7.86.8
Linux Azure Diagnostic extension (LAD) Elevation of Privilege Vulnerability
CVE-2026-23665NoNo--Important7.86.8
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2026-23674NoNo--Important7.56.5
Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability
CVE-2026-23651NoNo--Critical6.76.0
CVE-2026-26124NoNo--Critical6.76.0
Microsoft ACI Confidential Containers Information Disclosure Vulnerability
CVE-2026-26122NoNo--Critical6.55.7
Microsoft Authenticator Information Disclosure Vulnerability
CVE-2026-26123NoNo--Important5.54.8
Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
CVE-2026-26148NoNo--Important8.17.3
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-25167NoNo--Important7.46.4
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
CVE-2026-21536NoNo--Critical9.88.5
Microsoft Excel Information Disclosure Vulnerability
CVE-2026-26144NoNo--Critical7.56.5
Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-26112NoNo--Important7.86.8
CVE-2026-26107NoNo--Important7.86.8
CVE-2026-26108NoNo--Important7.86.8
CVE-2026-26109NoNo--Important8.47.3
Microsoft Office Elevation of Privilege Vulnerability
CVE-2026-26134NoNo--Important7.86.8
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-26113NoNo--Critical8.47.3
CVE-2026-26110NoNo--Critical8.47.3
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-26114NoNo--Important8.87.7
CVE-2026-26106NoNo--Important8.87.7
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-26105NoNo--Important8.17.1
Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability
CVE-2026-24283NoNo--Important8.87.7
Payment Orchestrator Service Elevation of Privilege Vulnerability
CVE-2026-26125NoNo--Critical8.67.7
Performance Counters for Windows Elevation of Privilege Vulnerability
CVE-2026-25165NoNo--Important7.86.8
Push message Routing Service Elevation of Privilege Vulnerability
CVE-2026-24282NoNo--Important5.54.8
SQL Server Elevation of Privilege Vulnerability
CVE-2026-21262YesNo--Important8.87.7
CVE-2026-26115NoNo--Important8.87.7
CVE-2026-26116NoNo--Important8.87.7
System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability
CVE-2026-20967NoNo--Important8.87.7
Win32k Elevation of Privilege Vulnerability
CVE-2026-24285NoNo--Important7.06.1
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability
CVE-2026-24291NoNo--Important7.86.8
Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability
CVE-2026-25186NoNo--Important5.54.8
Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
CVE-2026-23660NoNo--Important7.86.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-24293NoNo--Important7.86.8
CVE-2026-25176NoNo--Important7.86.8
CVE-2026-25178NoNo--Important7.06.1
CVE-2026-25179NoNo--Important7.06.1
Windows App Installer Spoofing Vulnerability
CVE-2026-23656NoNo--Important
Windows Authentication Elevation of Privilege Vulnerability
CVE-2026-25171NoNo--Important7.06.1
Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability
CVE-2026-23671NoNo--Important7.06.1
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2026-24292NoNo--Important7.86.8
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-25189NoNo--Important7.86.8
Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-24295NoNo--Important7.06.1
CVE-2026-24296NoNo--Important7.06.1
Windows Extensible File Allocation Table Elevation of Privilege Vulnerability
CVE-2026-25174NoNo--Important7.86.8
Windows Graphics Component Denial of Service Vulnerability
CVE-2026-25168NoNo--Important6.25.4
CVE-2026-25169NoNo--Important6.25.4
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-23668NoNo--Important7.06.1
Windows Graphics Component Information Disclosure Vulnerability
CVE-2026-25180NoNo--Important5.54.8
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-25170NoNo--Important7.06.1
Windows Kerberos Security Feature Bypass Vulnerability
CVE-2026-24297NoNo--Important6.55.7
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-24287NoNo--Important7.86.8
CVE-2026-24289NoNo--Important7.86.8
CVE-2026-26132NoNo--Important7.86.8
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2026-24288NoNo--Important6.85.9
Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-25175NoNo--Important7.86.8
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2026-23669NoNo--Important8.87.7
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-24290NoNo--Important7.86.8
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2026-23673NoNo--Important7.86.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-25172NoNo--Important8.87.7
CVE-2026-25173NoNo--Important8.07.0
CVE-2026-26111NoNo--Important8.87.7
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-24294NoNo--Important7.86.8
CVE-2026-26128NoNo--Important7.86.8
Windows Shell Link Processing Spoofing Vulnerability
CVE-2026-25185NoNo--Important5.34.6
Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability
CVE-2026-25166NoNo--Important7.86.8
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-25188NoNo--Important8.87.7
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-23672NoNo--Important7.86.8
Winlogon Elevation of Privilege Vulnerability
CVE-2026-25187NoNo--Important7.86.8

Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu

Twitter |

Keywords: [patch Tuesday](/tag.html?tag=patch Tuesday) Microsoft

0 comment(s)

My next class:

Application Security: Securing Web Apps, APIs, and MicroservicesOrlandoMar 29th - Apr 3rd 2026

Comments

Login here to join the discussion.

Top of page

×

modal content

Diary Archives