Microsoft Patch Tuesday March 2026 Fixes 79 Vulnerabilities, Including Two Zero-Days

Microsoft has released its March 2026 Patch Tuesday security updates, fixing 79 vulnerabilities across multiple products, including Windows, Microsoft Office, SQL Server, .NET Framework, Azure components, and Edge browser.

The update also addresses two publicly disclosed zero‑day vulnerabilities that could potentially expose enterprise environments to privilege escalation or service disruption if left unpatched.

Security teams are strongly advised to deploy the updates quickly because attackers often weaponize newly disclosed vulnerabilities shortly after patches are released.

March 2026 Patch Tuesday Overview

According to Microsoft’s security advisory, the March release fixes a total of 79 vulnerabilities across the Microsoft ecosystem.

The vulnerabilities are categorized as follows:

  • 3 Critical vulnerabilities
  • 76 Important or Low severity issues
  • 46 Elevation of Privilege vulnerabilities
  • 18 Remote Code Execution vulnerabilities
  • Multiple Information Disclosure, Spoofing, Tampering, and Denial‑of‑Service flaws

Elevation of privilege issues represents the largest category. These flaws allow attackers with limited access to gain higher permissions within a system, potentially leading to full administrative control.

Remote code execution (RCE) vulnerabilities are also particularly dangerous because attackers can exploit them to execute malicious code remotely, often without user interaction.

Microsoft also addressed two zero‑day vulnerabilities that had been publicly disclosed before the release of official patches.

Although Microsoft reports no evidence of active exploitation, public disclosure increases the likelihood that threat actors may attempt to develop exploits.

The two notable zero-day vulnerabilities include:

  • CVE-2026-21262 – SQL Server Elevation of Privilege Vulnerability
    Attackers with authorized network access could escalate privileges to administrative levels on affected SQL Server environments.
  • .NET Framework Denial-of-Service Vulnerability
    This flaw allows attackers to trigger service disruptions by causing .NET applications to crash or become unavailable, potentially affecting business operations.

Organizations running SQL Server databases or .NET applications should prioritize patch deployment to reduce the risk of service outages or privilege escalation attacks.

Patched Vulnerabilities

CVE IDVulnerability NameTypeSeverity
CVE IDVulnerability NameTypeSeverity
CVE-2024-29059.NET Framework Information Disclosure VulnerabilityInformation DisclosureImportant
CVE-2024-29057Microsoft Edge (Chromium-based) Spoofing VulnerabilitySpoofingLow
CVE-2024-28916Xbox Gaming Services Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26247Microsoft Edge Security Feature Bypass VulnerabilitySecurity Feature BypassLow
CVE-2024-26246Microsoft Edge Security Feature Bypass VulnerabilitySecurity Feature BypassLow
CVE-2024-26204Outlook for Android Information Disclosure VulnerabilityInformation DisclosureImportant
CVE-2024-26203Azure Data Studio Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26201Microsoft Intune Linux Agent Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26199Microsoft Office Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26198Microsoft Exchange Server Remote Code Execution VulnerabilityRemote Code ExecutionImportant
CVE-2024-26197Windows Standards-Based Storage Management Service Denial of Service VulnerabilityDenial of ServiceImportant
CVE-2024-26196Microsoft Edge for Android Information Disclosure VulnerabilityInformation DisclosureLow
CVE-2024-26192Microsoft Edge Information Disclosure VulnerabilityInformation DisclosureImportant
CVE-2024-26190Microsoft QUIC Denial of Service VulnerabilityDenial of ServiceImportant
CVE-2024-26188Microsoft Edge Spoofing VulnerabilitySpoofingLow
CVE-2024-26185Windows Compressed Folder Tampering VulnerabilityTamperingImportant
CVE-2024-26182Windows Kernel Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26181Windows Kernel Denial of Service VulnerabilityDenial of ServiceImportant
CVE-2024-26178Windows Kernel Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26177Windows Kernel Information Disclosure VulnerabilityInformation DisclosureImportant
CVE-2024-26176Windows Kernel Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26174Windows Kernel Information Disclosure VulnerabilityInformation DisclosureImportant
CVE-2024-26173Windows Kernel Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26170Windows Composite Image File System Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26169Windows Error Reporting Service Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26167Microsoft Edge for Android Spoofing VulnerabilitySpoofingLow
CVE-2024-26166Microsoft WDAC OLE DB Provider for SQL Server Remote Code Execution VulnerabilityRemote Code ExecutionImportant
CVE-2024-26165Visual Studio Code Elevation of Privilege VulnerabilityElevation of PrivilegeImportant
CVE-2024-26164Microsoft Django Backend for SQL Server Remote Code Execution VulnerabilityRemote Code ExecutionImportant
CVE-2024-26163Microsoft Edge Security Feature Bypass VulnerabilitySecurity Feature BypassLow

Security teams should take the following steps to reduce exposure:

  • Deploy the March 2026 Patch Tuesday updates immediately across Windows servers, workstations, and Microsoft applications.
  • Prioritize internet‑facing systems and critical infrastructure such as SQL Server and Exchange.
  • Test patches in a staging or QA environment before enterprise‑wide deployment.
  • Monitor SQL Server and .NET services for unusual access attempts or abnormal traffic patterns.
  • Review Microsoft Office security settings, as some vulnerabilities can be triggered through the preview pane.

Applying these updates promptly is critical because unpatched systems often become targets for ransomware groups and opportunistic attackers scanning the internet for vulnerable infrastructure.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories