{"id":12744,"date":"2026-03-15T10:20:51","date_gmt":"2026-03-15T10:20:51","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=12744"},"modified":"2026-03-15T10:20:51","modified_gmt":"2026-03-15T10:20:51","slug":"microsoft-patch-tuesday-march-2026-version-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=12744","title":{"rendered":"Microsoft Patch Tuesday, March 2026 Version \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><strong>Microsoft Corp.<\/strong> at this time pushed safety updates to repair a minimum of 77 vulnerabilities in its <strong>Home windows<\/strong> working methods and different software program. There aren&#8217;t any urgent \u201czero-day\u201d flaws this month (in comparison with February\u2019s 5 zero-day deal with), however as normal some patches could deserve extra fast consideration from organizations utilizing Home windows. Listed here are a couple of highlights from this month\u2019s Patch Tuesday.<\/p>\n<div id=\"attachment_73312\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-73312\" decoding=\"async\" class=\" wp-image-73312\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/03\/winupdatechecking.png\" alt=\"\" width=\"750\" height=\"446\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/03\/winupdatechecking.png 926w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/03\/winupdatechecking-768x457.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/03\/winupdatechecking-782x465.png 782w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\"\/><\/p>\n<p id=\"caption-attachment-73312\" class=\"wp-caption-text\">Picture: Shutterstock, @nwz.<\/p>\n<\/div>\n<p>Two of the bugs Microsoft patched at this time had been publicly disclosed beforehand. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-21262\" target=\"_blank\" rel=\"noopener\">CVE-2026-21262<\/a> is a weak spot that enables an attacker to raise their privileges on <strong>SQL Server 2016<\/strong> and later editions.<\/p>\n<p>\u201cThis isn\u2019t simply any elevation of privilege vulnerability, both; the advisory notes that a certified attacker can elevate privileges to sysadmin over a community,\u201d Rapid7\u2019s <strong>Adam Barnett<\/strong> stated. \u201cThe CVSS v3 base rating of 8.8 is slightly below the brink for crucial severity, since low-level privileges are required. It might be a brave defender who shrugged and deferred the patches for this one.\u201d<\/p>\n<p>The opposite publicly disclosed flaw is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-26127\" target=\"_blank\" rel=\"noopener\">CVE-2026-26127<\/a>, a vulnerability in functions working on <strong>.NET<\/strong>. Barnett stated the instant influence of exploitation is probably going restricted to denial of service by triggering a crash, with the potential for different sorts of assaults throughout a service reboot.<\/p>\n<p>It might hardly be a correct Patch Tuesday with out a minimum of one crucial <strong>Microsoft Workplace<\/strong> exploit, and this month doesn\u2019t disappoint. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-26113\" target=\"_blank\" rel=\"noopener\">CVE-2026-26113<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-26110\" target=\"_blank\" rel=\"noopener\">CVE-2026-26110<\/a> are each distant code execution flaws that may be triggered simply by viewing a booby-trapped message within the Preview Pane.<span id=\"more-73276\"\/><\/p>\n<p><strong>Satnam Narang<\/strong> at <strong>Tenable<\/strong> notes that simply over half (55%) of all Patch Tuesday CVEs this month are privilege escalation bugs, and of these, a half dozen had been rated \u201cexploitation extra probably\u201d \u2014 throughout Home windows Graphics Part, Home windows Accessibility Infrastructure, Home windows Kernel, Home windows SMB Server and Winlogon. These embrace:<\/p>\n<p>\u2013<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-24291\" target=\"_blank\" rel=\"noopener\">CVE-2026-24291<\/a>: Incorrect permission assignments throughout the Home windows Accessibility Infrastructure to succeed in SYSTEM (CVSS 7.8)<br \/>\u2013<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-24294\" target=\"_blank\" rel=\"noopener\">CVE-2026-24294<\/a>: Improper authentication within the core SMB part (CVSS 7.8)<br \/>\u2013<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-24289\" target=\"_blank\" rel=\"noopener\">CVE-2026-24289<\/a>: Excessive-severity reminiscence corruption and race situation flaw (CVSS 7.8)<br \/>\u2013<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-25187\" target=\"_blank\" rel=\"noopener\">CVE-2026-25187<\/a>: Winlogon course of weak spot found by Google Venture Zero (CVSS 7.8).<\/p>\n<p><strong>Ben McCarthy<\/strong>, lead cyber safety engineer at <strong>Immersive<\/strong>, known as consideration to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-21536\" target=\"_blank\" rel=\"noopener\">CVE-2026-21536<\/a>, a crucial distant code execution bug in a part known as the Microsoft Gadgets Pricing Program. Microsoft has already resolved the problem on their finish, and fixing it requires no motion on the a part of Home windows customers. However McCarthy says it\u2019s notable as one of many first vulnerabilities recognized by an AI agent and formally acknowledged with a CVE attributed to the Home windows working system. It was found by <strong>XBOW<\/strong>, a completely autonomous AI penetration testing agent.<\/p>\n<p>XBOW has persistently ranked at or close to the highest of the Hacker One bug bounty leaderboard for the previous yr. McCarthy stated CVE-2026-21536 demonstrates how AI brokers can determine crucial 9.8-rated vulnerabilities with out entry to supply code.<\/p>\n<p>\u201cThough Microsoft has already patched and mitigated the vulnerability, it highlights a shift towards AI-driven discovery of complicated vulnerabilities at rising pace,\u201d McCarthy stated. \u201cThis growth suggests AI-assisted vulnerability analysis will play a rising position within the safety panorama.\u201d<\/p>\n<p>Microsoft earlier supplied patches to handle 9 browser vulnerabilities, which aren&#8217;t included within the Patch Tuesday depend above. As well as, Microsoft issued a vital out-of-band (emergency) <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/support.microsoft.com\/en-us\/topic\/march-2-2026-kb5082314-os-build-20348-4776-out-of-band-606518e5-28d2-4ebe-be25-26287e2fc703\" target=\"_blank\" rel=\"noopener\">replace on March 2<\/a> for <strong>Home windows Server 2022<\/strong> to handle a certificates renewal challenge with passwordless authentication expertise Home windows Hi there for Enterprise.<\/p>\n<p>Individually, <strong>Adobe<\/strong> shipped updates to repair 80 vulnerabilities \u2014 a few of them crucial in severity \u2014 in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/helpx.adobe.com\/security\/Home.html\" target=\"_blank\" rel=\"noopener\">quite a lot of merchandise<\/a>, together with <strong>Acrobat<\/strong> and <strong>Adobe Commerce<\/strong>. <strong>Mozilla Firefox<\/strong> v. 148.0.2 resolves three excessive severity CVEs.<\/p>\n<p>For an entire breakdown of all of the patches Microsoft launched at this time, take a look at the SANS Web Storm Heart\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/isc.sans.edu\/forums\/diary\/Microsoft%20Patch%20Tuesday%20March%202026\/32782\/\" target=\"_blank\" rel=\"noopener\">Patch Tuesday submit<\/a>. Home windows enterprise admins who want to keep abreast of any information about problematic updates, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.askwoody.com\" target=\"_blank\" rel=\"noopener\">AskWoody.com<\/a> is all the time value a go to. Please be at liberty to drop a remark under should you expertise any points apply this month\u2019s patches.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Corp. at this time pushed safety updates to repair a minimum of 77 vulnerabilities in its Home windows working methods and different software program. There aren&#8217;t any urgent \u201czero-day\u201d flaws this month (in comparison with February\u2019s 5 zero-day deal with), however as normal some patches could deserve extra fast consideration from organizations utilizing Home [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":12746,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[406,262,1282,618,1077,211,1078],"class_list":["post-12744","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-edition","tag-krebs","tag-march","tag-microsoft","tag-patch","tag-security","tag-tuesday"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/12744","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=12744"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/12744\/revisions"}],"predecessor-version":[{"id":12745,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/12744\/revisions\/12745"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/12746"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=12744"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=12744"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=12744"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-09 03:43:57 UTC -->