Skip to content
Microsoft Patch Tuesday – March 2026

Microsoft Patch Tuesday – March 2026

Lansweeper March 10, 2026

Patch Tuesday is once again upon us. As always, our team has put together the monthly Patch Tuesday Report to help you manage your update progress. The audit report gives you a quick and clear overview of your Windows machines and their patching status. The March 2026 edition of Patch Tuesday brings us 88 fixes, with 3 rated as critical. We’ve listed the most important changes below.

CVE-2026-26144 is a critical information disclosure flaw in Microsoft Excel caused by improper input neutralization during web page generation. An unauthenticated attacker could exploit this issue over the network without requiring user interaction to expose sensitive information, potentially by abusing Copilot Agent mode to trigger unintended outbound data exfiltration in a zero-click scenario.

Microsoft notes that the Preview Pane is not a valid attack path, and exploitation is currently considered unlikely, with no evidence of public disclosure or active abuse at the time of release.

The last two critical vulnerabilites this month are both in Microsoft Office. CVE-2026-26113 and CVE-2026-26110 , both describe critical remote code execution risks that could allow unauthorized code to run locally on an affected system.

CVE-2026-26113 stems from an untrusted pointer dereference, while CVE-2026-26110 is caused by a type confusion issue involving incompatible resource handling. In both cases, Microsoft rates the attack complexity as low, requires no privileges or user interaction, and notes that the Preview Pane can serve as an attack vector. Although these flaws are labeled as remote code execution, Microsoft clarifies that the exploitation itself occurs locally on the device, meaning code must ultimately be triggered from the local machine.

Neither vulnerability was publicly disclosed or observed in active attacks at release, and exploitation is currently assessed as less likely, but affected organizations should still install all applicable security updates for impacted Office products.

Last but not least are two of the more concerning Windows flaws addressed this month, CVE-2026-26132 and CVE-2026-24289 , both elevation of privilege vulnerabilities in the Windows Kernel caused by a use-after-free condition. In each case, an attacker with low privileges could exploit the issue locally without user interaction to gain higher-level access on the system.

Microsoft rates both vulnerabilities as more likely to be exploited, which makes them especially notable for defenders, since kernel-level privilege escalation bugs are often used to turn a limited compromise into full control of a device.

While CVE-2026-26132 could allow an attacker to obtain administrator privileges, CVE-2026-24289 is even more severe in outcome, as successful exploitation could result in SYSTEM-level access.

To help manage your update progress, we’ve created the Patch Tuesday Audit that checks if the assets in your network are on the latest patch updates. The report has been color-coded to see which machines are up-to-date and which ones still need to be updated. As always, system administrators are urged to update their environment as soon as possible to ensure all endpoints are secured.

The Lansweeper Patch Tuesday report is automatically added to your Lansweeper Site. Lansweeper Sites is included in all our licenses without any additional cost and allows you to federate all your installations into one single view so all you need to do is look at one report, automatically added every patch Tuesday!