logo

Patch Tuesday: March 2026 (Expel’s version)

ID: 274e05d4-eab3-5490-b37d-abd891310eae

STIX ID: report--274e05d4-eab3-5490-b37d-abd891310eae

Feed Name: Expel Blog

Threat Score
75/100

Date Published: 2026-03-10

Date Updated: 2026-04-27

...
...

This Patch Tuesday briefing covers 79 new CVEs (three critical), calls out three high-priority fixes — an SQL Server elevation-of-privilege (CVE-2026-21262), a .NET denial-of-service (CVE-2026-26127), and a zero-click Excel information disclosure that can cause Microsoft Copilot to leak data (CVE-2026-26144) — and documents active exploitation of the abandoned Kaswara WPBakery Page Builder plugin (CVE-2021-24284) being used to deploy XMRig cryptomining software; recommended actions include applying updates, removing unsupported plugins, and auditing upload directories for malicious PHP files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.