Back Bleepingcomputer Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
This Patch Tuesday also addresses three "Critical" vulnerabilities, 2 of which are remote code execution flaws and the other is an information disclosure flaw.
The number of bugs in each vulnerability category is listed below:
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today. Therefore, the number of flaws does not include 9 Microsoft Edge flaws, Mariner, Payment Orchestrator Service, Azure, and Microsoft Devices Pricing Program flaws fixed earlier this month.
This month's Patch Tuesday fixes two publicly disclosed zero-day vulnerabilities, with none of them known to be exploited in attacks.
Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.
The two publicly disclosed zero-days are:
CVE-2026-21262 - SQL Server Elevation of Privilege Vulnerability
Microsoft has patched a publicly disclosed SQL Server elevation-of-privilege flaw that grants SQLAdmin privileges.
"Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network," explains Microsoft.
Microsoft has credited Erland Sommarskog with discovering this flaw.
CVE-2026-26127 - .NET Denial of Service Vulnerability
Microsoft has patched a publicly disclosed .NET denial of service flaw.
"Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network," explains Microsoft.
This flaw was attributed to an anonymous researcher.
Microsoft has also fixed two remote code execution bugs ( CVE-2026-26110 and CVE-2026-26113 ), both in Microsoft Office, which can be exploited via the preview pane. Therefore, users should prioritize updating the application.
Of particular interest is the Microsoft Excel information disclosure flaw ( CVE-2026-26144 ), as it could be used to exfiltrate data via Microsoft Copilot.
"An attacker who successfully exploited this vulnerability could potentially cause Copilot Agent mode to exfiltrate data via unintended network egress, enabling zero-click information disclosure attack," explains Microsoft.
Other vendors who released updates or advisories in March 2026 include:
Below is the complete list of resolved vulnerabilities in the March 2026 Patch Tuesday updates.
To access the full description of each vulnerability and the systems it affects, you can view the full report here .
Update 2/10/26: Added information how CVE-2026-21533 and CVE-2026-21525 are exploited.
Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.
Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
