March 2026 Patch Tuesday fixes two zero-day vulnerabilities
ID: d4dcc89c-64f0-5eac-936e-70ca1b17651d
STIX ID: report--d4dcc89c-64f0-5eac-936e-70ca1b17651d
Feed Name: Malwarebytes Blog
Microsoft's Patch Tuesday fixes 79 CVEs, including two notable issues: CVE-2026-21262 (SQL Server privilege escalation, CVSS 8.8) which can allow an authenticated attacker to escalate to sysadmin over the network, and CVE-2026-26127 (.NET 9.0/10.0 denial-of-service, CVSS 7.5) affecting runtimes across Windows/macOS/Linux; additional Office RCE and Excel information-disclosure flaws are also addressed. The advisory reports no known active exploitation of these flaws, emphasizes applying the available patches immediately, and includes step-by-step Windows Update instructions to ensure systems are protected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
