Skip to main content
QUIETLYTIC
Advisory

Microsoft Patch Tuesday March 2026: 462 Vulnerabilities Fixed

Microsoft's March 10, 2026 Patch Tuesday fixed 462 vulnerabilities (26 critical, 187 important) — none are currently listed as actively exploited, per CISA…

Microsoft Patch Tuesday March 2026: 462 Vulnerabilities Fixed — Advisory research covering CVE-2026-32169, CVE-2025-69720, CVE-2026-21536, CVE-2026-32191, CVE-2026-32194, CVE-2026-3381, CVE-2026-33937, CVE-2026-4176, CVE-2026-23395, CVE-2026-23658, CVE-2026-23659, CVE-2026-26125, CVE-2026-26138, CVE-2026-26139, CVE-2026-26110, CVE-2026-26113, CVE-2026-26144, CVE-2026-23651, CVE-2026-26124, CVE-2026-26120, CVE-2026-26122, CVE-2026-26136, CVE-2026-24299, CVE-2026-26137, CVE-2026-4739, CVE-2026-4746, CVE-2026-26030, CVE-2026-34714, CVE-2025-67030, CVE-2026-20967, CVE-2026-21262, CVE-2026-23654, CVE-2026-23669, CVE-2026-24283, CVE-2026-25177, CVE-2026-25188, CVE-2026-26106, CVE-2026-26114, CVE-2026-26115, CVE-2026-26116, CVE-2026-26118, CVE-2006-10003, CVE-2026-33216, CVE-2026-5121, CVE-2026-0031, CVE-2026-0038, CVE-2026-23374, CVE-2026-26109, CVE-2026-27654, CVE-2026-31788, CVE-2026-33941, CVE-2026-26105, CVE-2026-26148, CVE-2026-33186, CVE-2026-33938, CVE-2026-33940, CVE-2026-25172, CVE-2026-25173, CVE-2026-26111, CVE-2025-69650, CVE-2026-0032, CVE-2026-23231, CVE-2026-23243, CVE-2026-23268, CVE-2026-23281, CVE-2026-23233, CVE-2026-23234, CVE-2026-23235, CVE-2026-23287, CVE-2026-23308, CVE-2026-23336, CVE-2026-23359, CVE-2026-23372, CVE-2026-23391, CVE-2026-23660, CVE-2026-23665, CVE-2026-23672, CVE-2026-23673, CVE-2026-24287, CVE-2026-24289, CVE-2026-24290, CVE-2026-24291, CVE-2026-24292, CVE-2026-24293, CVE-2026-24294, CVE-2026-25165, CVE-2026-25166, CVE-2026-25174, CVE-2026-25175, CVE-2026-25176, CVE-2026-25187, CVE-2026-25189, CVE-2026-25190, CVE-2026-26107, CVE-2026-26108, CVE-2026-26112, CVE-2026-26117, CVE-2026-26128, CVE-2026-26131, CVE-2026-26132, CVE-2026-26134, CVE-2026-26141, CVE-2026-27784, CVE-2026-32647, CVE-2026-4775, CVE-2026-23318, CVE-2026-26017, CVE-2026-33636, CVE-2026-1519, CVE-2026-21710, CVE-2026-23293, CVE-2025-70873, CVE-2026-23300, CVE-2026-23661, CVE-2026-23662, CVE-2026-23664, CVE-2026-23674, CVE-2026-25075, CVE-2026-25181, CVE-2026-25679, CVE-2026-26018, CVE-2026-26121, CVE-2026-26127, CVE-2026-26130, CVE-2026-27135, CVE-2026-27142, CVE-2026-27601, CVE-2026-27651, CVE-2026-29785, CVE-2026-30922, CVE-2026-3104, CVE-2026-32141, CVE-2026-32241, CVE-2026-32287, CVE-2026-32597, CVE-2026-32748, CVE-2026-3336, CVE-2026-3338, CVE-2026-33416, CVE-2026-33526, CVE-2026-33554, CVE-2026-33671, CVE-2026-33891, CVE-2026-33895, CVE-2026-33939, CVE-2026-3547, CVE-2026-3805, CVE-2026-4046, CVE-2026-4111, CVE-2026-4424
Severity
Critical
Confidence
High
Status
Active

Full CVE Roster

All 150 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search — 3 flagged as actively exploited (KEV).

CVE ID Title CVSS Severity KEV
CVE-2026-32169 Azure Cloud Shell Elevation of Privilege Vulnerability 10.0 critical
CVE-2025-69720 The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. 9.8 critical
CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability 9.8 critical
CVE-2026-32191 Microsoft Bing Images Remote Code Execution Vulnerability 9.8 critical
CVE-2026-32194 Microsoft Bing Images Remote Code Execution Vulnerability 9.8 critical
CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib 9.8 critical
CVE-2026-33937 Handlebars.js has JavaScript Injection via AST Type Confusion 9.8 critical
CVE-2026-4176 Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib 9.8 critical
CVE-2026-23395 Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ 9.1 critical
CVE-2026-23658 Azure DevOps: msazure Elevation of Privilege Vulnerability 8.6 critical
CVE-2026-23659 Azure Data Factory Information Disclosure Vulnerability 8.6 critical
CVE-2026-26125 Payment Orchestrator Service Elevation of Privilege Vulnerability 8.6 critical
CVE-2026-26138 Microsoft Purview Elevation of Privilege Vulnerability 8.6 critical
CVE-2026-26139 Microsoft Purview Elevation of Privilege Vulnerability 8.6 critical
CVE-2026-26110 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-26113 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-26144 Microsoft Excel Information Disclosure Vulnerability 7.5 critical
CVE-2026-23651 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability 6.7 critical
CVE-2026-26124 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability 6.7 critical
CVE-2026-26120 Microsoft Bing Tampering Vulnerability 6.5 critical
CVE-2026-26122 Microsoft ACI Confidential Containers Information Disclosure Vulnerability 6.5 critical
CVE-2026-26136 Microsoft Copilot Information Disclosure Vulnerability 6.5 critical
CVE-2026-24299 M365 Copilot Information Disclosure Vulnerability 5.3 critical
CVE-2026-26137 Microsoft Exchange Elevation of Privilege Vulnerability — critical
CVE-2026-4739 Integer overflow vulnerabilities in InsightSoftwareConsortium/ITK — critical
CVE-2026-4746 Heap Buffer Over-Write Vulenrabilty in timeplus-io/proton — critical
CVE-2026-26030 GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable 9.9 high
CVE-2026-34714 Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE. 9.2 high
CVE-2025-67030 Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code 8.8 high
CVE-2026-20967 System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability 8.8 high
CVE-2026-21262 SQL Server Elevation of Privilege Vulnerability 8.8 high Yes
CVE-2026-23654 GitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability 8.8 high
CVE-2026-23669 RPC Runtime Library Remote Code Execution Vulnerability 8.8 high
CVE-2026-24283 Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability 8.8 high
CVE-2026-25177 Active Directory Domain Services Elevation of Privilege Vulnerability 8.8 high
CVE-2026-25188 Windows Telephony Service Elevation of Privilege Vulnerability 8.8 high
CVE-2026-26106 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8 high
CVE-2026-26114 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8 high
CVE-2026-26115 SQL Server Elevation of Privilege Vulnerability 8.8 high
CVE-2026-26116 SQL Server Elevation of Privilege Vulnerability 8.8 high
CVE-2026-26118 Azure MCP Server Tools Elevation of Privilege Vulnerability 8.8 high
CVE-2006-10003 XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack 8.6 high
CVE-2026-33216 NATS has MQTT plaintext password disclosure 8.6 high
CVE-2026-5121 Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing 8.6 high
CVE-2026-0031 In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. 8.4 high
CVE-2026-0038 In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. 8.4 high
CVE-2026-23374 blktrace: fix __this_cpu_read/write in preemptible context 8.4 high
CVE-2026-26109 Microsoft Excel Remote Code Execution Vulnerability 8.4 high
CVE-2026-27654 NGINX ngx_http_dav_module vulnerability 8.2 high
CVE-2026-31788 xen/privcmd: restrict usage in unprivileged domU 8.2 high
CVE-2026-33941 Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options 8.2 high
CVE-2026-26105 Microsoft SharePoint Server Spoofing Vulnerability 8.1 high
CVE-2026-26148 Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability 8.1 high
CVE-2026-33186 gRPC-Go has an authorization bypass via missing leading slash in :path 8.1 high
CVE-2026-33938 Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block 8.1 high
CVE-2026-33940 Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial 8.1 high
CVE-2026-25172 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.0 high
CVE-2026-25173 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.0 high
CVE-2026-26111 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.0 high
CVE-2025-69650 GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. 7.8 high
CVE-2026-0032 In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. 7.8 high
CVE-2026-23231 netfilter: nf_tables: fix use-after-free in nf_tables_addchain() 7.8 high
CVE-2026-23243 RDMA/umad: Reject negative data_len in ib_umad_write 7.8 high
CVE-2026-23268 apparmor: fix unprivileged local user can do privileged policy management 7.8 high
CVE-2026-23281 wifi: libertas: fix use-after-free in lbs_free_adapter() 7.8 high
CVE-2026-23233 f2fs: fix to avoid mapping wrong physical block for swapfile 7.8 high
CVE-2026-23234 f2fs: fix to avoid UAF in f2fs_write_end_io() 7.8 high
CVE-2026-23235 f2fs: fix out-of-bounds access in sysfs attribute read/write 7.8 high
CVE-2026-23287 irqchip/sifive-plic: Fix frozen interrupt due to affinity setting 7.8 high
CVE-2026-23308 pinctrl: equilibrium: fix warning trace on load 7.8 high
CVE-2026-23336 wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() 7.8 high
CVE-2026-23359 bpf: Fix stack-out-of-bounds write in devmap 7.8 high
CVE-2026-23372 nfc: rawsock: cancel tx_work before socket teardown 7.8 high
CVE-2026-23391 netfilter: xt_CT: drop pending enqueued packets on template removal 7.8 high
CVE-2026-23660 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability 7.8 high
CVE-2026-23665 Linux Azure Diagnostic extension (LAD) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-23672 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-23673 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-24287 Windows Kernel Elevation of Privilege Vulnerability 7.8 high
CVE-2026-24289 Windows Kernel Elevation of Privilege Vulnerability 7.8 high
CVE-2026-24290 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2026-24291 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-24292 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-24293 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.8 high
CVE-2026-24294 Windows SMB Server Elevation of Privilege Vulnerability 7.8 high
CVE-2026-25165 Performance Counters for Windows Elevation of Privilege Vulnerability 7.8 high
CVE-2026-25166 Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability 7.8 high
CVE-2026-25174 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability 7.8 high
CVE-2026-25175 Windows NTFS Elevation of Privilege Vulnerability 7.8 high
CVE-2026-25176 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.8 high
CVE-2026-25187 Winlogon Elevation of Privilege Vulnerability 7.8 high Yes
CVE-2026-25189 Windows DWM Core Library Elevation of Privilege Vulnerability 7.8 high
CVE-2026-25190 Windows GDI Remote Code Execution Vulnerability 7.8 high
CVE-2026-26107 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-26108 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-26112 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-26117 Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26128 Windows SMB Server Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26131 .NET Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26132 Windows Kernel Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26134 Microsoft Office Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26141 Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27784 NGINX ngx_http_mp4_module vulnerability 7.8 high
CVE-2026-32647 NGINX ngx_http_mp4_module vulnerability 7.8 high
CVE-2026-4775 Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing 7.8 high
CVE-2026-23318 ALSA: usb-audio: Use correct version for UAC3 header validation 7.7 high
CVE-2026-26017 CoreDNS ACL Bypass 7.7 high
CVE-2026-33636 LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64 7.6 high
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation 7.5 high
CVE-2026-21710 A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x** 7.5 high
CVE-2026-23293 net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled 7.5 high
CVE-2025-70873 An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. 7.5 high
CVE-2026-23300 net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop 7.5 high
CVE-2026-23661 Azure IoT Explorer Information Disclosure Vulnerability 7.5 high
CVE-2026-23662 Azure IoT Explorer Information Disclosure Vulnerability 7.5 high
CVE-2026-23664 Azure IoT Explorer Information Disclosure Vulnerability 7.5 high
CVE-2026-23674 MapUrlToZone Security Feature Bypass Vulnerability 7.5 high
CVE-2026-25075 strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow 7.5 high
CVE-2026-25181 GDI+ Information Disclosure Vulnerability 7.5 high
CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url 7.5 high
CVE-2026-26018 CoreDNS Loop Detection Denial of Service Vulnerability 7.5 high
CVE-2026-26121 Azure IOT Explorer Spoofing Vulnerability 7.5 high
CVE-2026-26127 .NET Denial of Service Vulnerability 7.5 high Yes
CVE-2026-26130 ASP.NET Core Denial of Service Vulnerability 7.5 high
CVE-2026-27135 nghttp2 Denial of service: Assertion failure due to the missing state validation 7.5 high
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template 7.5 high
CVE-2026-27601 Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack 7.5 high
CVE-2026-27651 NGINX ngx_mail_auth_http_module vulnerability 7.5 high
CVE-2026-29785 NATS Server panic via malicious compression on leafnode port 7.5 high
CVE-2026-30922 pyasn1 Vulnerable to Denial of Service via Unbounded Recursion 7.5 high
CVE-2026-3104 Memory leak in code preparing DNSSEC proofs of non-existence 7.5 high
CVE-2026-32141 flatted: Unbounded recursion DoS in parse() revive phase 7.5 high
CVE-2026-32241 Flannel vulnerable to cross-node remote code execution via extension backend BackendData injection 7.5 high
CVE-2026-32287 Infinite loop in github.com/antchfx/xpath 7.5 high
CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) 7.5 high
CVE-2026-32748 Squid has Denial of Service in ICP Response handling 7.5 high
CVE-2026-3336 PKCS7_verify Certificate Chain Validation Bypass in AWS-LC 7.5 high
CVE-2026-3338 PKCS7_verify Signature Validation Bypass in AWS-LC 7.5 high
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` 7.5 high
CVE-2026-33526 Squid vulnerable to Denial of Service in ICP Request handling 7.5 high
CVE-2026-33554 ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermic 7.5 high
CVE-2026-33671 Picomatch has a ReDoS vulnerability via extglob quantifiers 7.5 high
CVE-2026-33891 Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input 7.5 high
CVE-2026-33895 Forge has signature forgery in Ed25519 due to missing S > L check 7.5 high
CVE-2026-33939 Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation 7.5 high
CVE-2026-3547 wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation 7.5 high
CVE-2026-3805 use after free in SMB connection reuse 7.5 high
CVE-2026-4046 iconv crash due to assertion failure with untrusted input 7.5 high
CVE-2026-4111 Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive 7.5 high
CVE-2026-4424 Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing 7.5 high

Microsoft’s March 10, 2026 Patch Tuesday release covers 462 CVEs: 26 rated critical, 187 rated important, and 142 rated moderate. Of these, none are currently listed as actively exploited.

Severity Breakdown

Severity Count
Critical 26
Important 187
Moderate 142
Actively exploited (CISA KEV) 0

Highest-Severity Vulnerabilities

Top 20 of 462 total, by CVSS/severity:

CVE Title CVSS
CVE-2026-32169 Azure Cloud Shell Elevation of Privilege Vulnerability 10.0
CVE-2026-26030 GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable 9.9
CVE-2025-69720 The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c. 9.8
CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability 9.8
CVE-2026-32191 Microsoft Bing Images Remote Code Execution Vulnerability 9.8
CVE-2026-32194 Microsoft Bing Images Remote Code Execution Vulnerability 9.8
CVE-2026-3381 Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib 9.8
CVE-2026-33937 Handlebars.js has JavaScript Injection via AST Type Confusion 9.8
CVE-2026-4176 Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib 9.8
CVE-2026-34714 Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE. 9.2
CVE-2026-23395 Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ 9.1
CVE-2025-67030 Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code 8.8
CVE-2026-20967 System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability 8.8
CVE-2026-21262 SQL Server Elevation of Privilege Vulnerability 8.8
CVE-2026-23654 GitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability 8.8
CVE-2026-23669 RPC Runtime Library Remote Code Execution Vulnerability 8.8
CVE-2026-24283 Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability 8.8
CVE-2026-25177 Active Directory Domain Services Elevation of Privilege Vulnerability 8.8
CVE-2026-25188 Windows Telephony Service Elevation of Privilege Vulnerability 8.8
CVE-2026-26106 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8

CVSS scores are sourced directly from Microsoft’s CVRF data as of March 10, 2026; exploitation status is cross-checked against CISA’s KEV catalog. Later re-scoring by NVD can shift a CVE’s score after this report was generated.

Why This Matters

No vulnerabilities in this release are yet listed in CISA’s Known Exploited Vulnerabilities catalog, but that can change quickly once a patch is public and attackers reverse-engineer it. Organizations should prioritize the critical- and important-rated CVEs above, especially any with public proof-of-concept exploits.

Frequently Asked Questions

How many vulnerabilities did Microsoft patch in March 2026? 462 CVEs, per Microsoft’s March 10, 2026 Patch Tuesday release.

Were any March 2026 Patch Tuesday vulnerabilities actively exploited? Not as of March 10, 2026, per CISA’s Known Exploited Vulnerabilities (KEV) catalog — this can change as exploitation is discovered after release.


Data sourced from Microsoft Security Response Center (MSRC) CVRF v3.0 and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated March 10, 2026. See more vulnerability research.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 Microsoft Security Response Center (MSRC)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools