How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
March 2026 Patch Tuesday: Microsoft fixed 78 vulnerabilities, 3 of them Critical. None was known to be exploited on the day. Released Tue 10 Mar 2026.
- 78vulnerabilities fixed
- 3Critical
- 0exploited before the fix
- 2publicly disclosed
- 0now on CISA KEV
By type: 43 elevation of privilege, 16 remote code execution, 9 information disclosure, 4 spoofing, 4 denial of service, 2 security feature bypass.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.
| CVE | What | Severity | CVSS | Why first |
|---|---|---|---|---|
CVE-2026-21262 | Microsoft SQL Server Elevation of Privilege | Important | 8.8 | Publicly disclosed |
CVE-2026-26127 | .NET Denial of Service | Important | 7.5 | Publicly disclosed |
Critical (3)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2026-26110 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-26113 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-26144 | Microsoft Excel Information Disclosure | Information Disclosure | 7.5 |
Added to CISA KEV in March 2026 (26)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2026-3055 | Citrix NetScaler | Out-of-Bounds Read | 30 Mar | 2 Apr 2026 | |
CVE-2025-53521 | F5 BIG-IP | Stack-Based Buffer Overflow | 27 Mar | 30 Mar 2026 | |
CVE-2026-33634 | Aquasecurity Trivy | Embedded Malicious Code | 26 Mar | 9 Apr 2026 | |
CVE-2026-33017 | Langflow Langflow | Langflow Code Injection | 25 Mar | 8 Apr 2026 | |
CVE-2025-31277 | Apple Multiple Products | Buffer Overflow | 20 Mar | 3 Apr 2026 | |
CVE-2025-32432 | Craft CMS Craft CMS | Craft CMS Code Injection | 20 Mar | 3 Apr 2026 | |
CVE-2025-43510 | Apple Multiple Products | Improper Locking | 20 Mar | 3 Apr 2026 | |
CVE-2025-43520 | Apple Multiple Products | Classic Buffer Overflow | 20 Mar | 3 Apr 2026 | |
CVE-2025-54068 | Laravel Livewire | Code Injection | 20 Mar | 3 Apr 2026 | |
CVE-2026-20131 | Cisco Secure Firewall Management Center (FMC) | Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data | 19 Mar | 22 Mar 2026 | Known |
CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) | Cross-Site Scripting | 18 Mar | 1 Apr 2026 | |
CVE-2026-20963 | Microsoft SharePoint | Deserialization of Untrusted Data | 18 Mar | 21 Mar 2026 | |
CVE-2025-47813 | Wing FTP Server Wing FTP Server | Wing FTP Server Information Disclosure | 16 Mar | 30 Mar 2026 | |
CVE-2026-3909 | Google Skia | Out-of-Bounds Write | 13 Mar | 27 Mar 2026 | |
CVE-2026-3910 | Google Chromium V8 | Improper Restriction of Operations Within the Bounds of a Memory Buffer | 13 Mar | 27 Mar 2026 | |
CVE-2025-68613 | n8n n8n | n8n Improper Control of Dynamically-Managed Code Resources | 11 Mar | 25 Mar 2026 | |
CVE-2021-22054 | Omnissa Workspace One UEM | Omnissa Workspace ONE Server-Side Request Forgery | 9 Mar | 23 Mar 2026 | |
CVE-2025-26399 | SolarWinds Web Help Desk | Deserialization of Untrusted Data | 9 Mar | 12 Mar 2026 | Known |
CVE-2026-1603 | Ivanti Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Authentication Bypass | 9 Mar | 23 Mar 2026 | |
CVE-2017-7921 | Hikvision Multiple Products | Improper Authentication | 5 Mar | 26 Mar 2026 | |
CVE-2021-22681 | Rockwell Multiple Products | Insufficient Protected Credentials | 5 Mar | 26 Mar 2026 | |
CVE-2021-30952 | Apple Multiple Products | Integer Overflow or Wraparound | 5 Mar | 26 Mar 2026 | |
CVE-2023-41974 | Apple iOS and iPadOS | Use-After-Free | 5 Mar | 26 Mar 2026 | |
CVE-2023-43000 | Apple Multiple Products | Apple Multiple products Use-After-Free | 5 Mar | 26 Mar 2026 | |
CVE-2026-21385 | Qualcomm Multiple Chipsets | Memory Corruption | 3 Mar | 24 Mar 2026 | |
CVE-2026-22719 | Broadcom VMware Aria Operations | Command Injection | 3 Mar | 24 Mar 2026 |
All 78 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2026-26110 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2026-26113 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2026-26144 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Critical | 7.5 |
CVE-2026-20967 | System Center Operations Manager | System Center Operations Manager (SCOM) Elevation of Privilege | Important | 8.8 |
CVE-2026-21262 | SQL Server | Microsoft SQL Server Elevation of Privilege | Important | 8.8 |
CVE-2026-23654 | GitHub Repo: zero-shot-scfoundation | GitHub: Zero Shot SCFoundation Remote Code Execution | Important | 8.8 |
CVE-2026-23669 | RPC Runtime | RPC Runtime Library Remote Code Execution | Important | 8.8 |
CVE-2026-24283 | Windows File Server | Multiple UNC Provider Kernel Driver Elevation of Privilege | Important | 8.8 |
CVE-2026-25177 | Active Directory Domain Services | Active Directory Domain Services Elevation of Privilege | Important | 8.8 |
CVE-2026-25188 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 8.8 |
CVE-2026-26106 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-26114 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-26115 | SQL Server | SQL Server Elevation of Privilege | Important | 8.8 |
CVE-2026-26116 | SQL Server | SQL Server Elevation of Privilege | Important | 8.8 |
CVE-2026-26118 | Azure MCP Server | Azure MCP Server Tools Elevation of Privilege | Important | 8.8 |
CVE-2026-26109 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 8.4 |
CVE-2026-26105 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 8.1 |
CVE-2026-26148 | Azure Entra ID | Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege | Important | 8.1 |
CVE-2026-25172 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Important | 8.0 |
CVE-2026-25173 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Important | 8.0 |
CVE-2026-26111 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Important | 8.0 |
CVE-2026-23660 | Azure Portal Windows Admin Center | Windows Admin Center in Azure Portal Elevation of Privilege | Important | 7.8 |
CVE-2026-23665 | Azure Linux Virtual Machines | Linux Azure Diagnostic extension (LAD) Elevation of Privilege | Important | 7.8 |
CVE-2026-23672 | Windows Universal Disk Format File System Driver (UDFS) | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege | Important | 7.8 |
CVE-2026-23673 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Elevation of Privilege | Important | 7.8 |
CVE-2026-24287 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-24289 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-24290 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2026-24291 | Windows Accessibility Infrastructure (ATBroker.exe) | Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege | Important | 7.8 |
CVE-2026-24292 | Connected Devices Platform Service (Cdpsvc) | Windows Connected Devices Platform Service Elevation of Privilege | Important | 7.8 |
CVE-2026-24293 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-24294 | Windows SMB Server | Windows SMB Server Elevation of Privilege | Important | 7.8 |
CVE-2026-25165 | Windows Performance Counters | Performance Counters for Windows Elevation of Privilege | Important | 7.8 |
CVE-2026-25166 | Windows System Image Manager | Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution | Important | 7.8 |
CVE-2026-25174 | Windows Extensible File Allocation | Windows Extensible File Allocation Table Elevation of Privilege | Important | 7.8 |
CVE-2026-25175 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.8 |
CVE-2026-25176 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-25187 | Winlogon | Winlogon Elevation of Privilege | Important | 7.8 |
CVE-2026-25189 | Windows DWM Core Library | Windows DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2026-25190 | Windows GDI | Windows GDI Remote Code Execution | Important | 7.8 |
CVE-2026-26107 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-26108 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-26112 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-26117 | Azure Windows Virtual Machine Agent | Arc Enabled Servers – Azure Connected Machine Agent Elevation of Privilege | Important | 7.8 |
CVE-2026-26128 | Windows SMB Server | Windows SMB Server Elevation of Privilege | Important | 7.8 |
CVE-2026-26131 | .NET | .NET Elevation of Privilege | Important | 7.8 |
CVE-2026-26132 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-26134 | Microsoft Office | Microsoft Office Elevation of Privilege | Important | 7.8 |
CVE-2026-26141 | Azure Arc | Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege | Important | 7.8 |
CVE-2026-23661 | Azure IoT Explorer | Azure IoT Explorer Information Disclosure | Important | 7.5 |
CVE-2026-23662 | Azure IoT Explorer | Azure IoT Explorer Information Disclosure | Important | 7.5 |
CVE-2026-23664 | Azure IoT Explorer | Azure IoT Explorer Information Disclosure | Important | 7.5 |
CVE-2026-23674 | Windows MapUrlToZone | MapUrlToZone Security Feature Bypass | Important | 7.5 |
CVE-2026-25181 | Windows GDI+ | GDI+ Information Disclosure | Important | 7.5 |
CVE-2026-26121 | Azure IoT Explorer | Azure IOT Explorer Spoofing | Important | 7.5 |
CVE-2026-26127 | .NET | .NET Denial of Service | Important | 7.5 |
CVE-2026-26130 | ASP.NET Core | ASP.NET Core Denial of Service | Important | 7.5 |
CVE-2026-25167 | Windows Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.4 |
CVE-2026-23667 | Broadcast DVR | Broadcast DVR Elevation of Privilege | Important | 7.0 |
CVE-2026-23668 | Microsoft Graphics Component | Windows Graphics Component Elevation of Privilege | Important | 7.0 |
CVE-2026-23671 | Windows Bluetooth RFCOM Protocol Driver | Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-24285 | Windows Win32K | Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-24295 | Windows Device Association Service | Windows Device Association Service Elevation of Privilege | Important | 7.0 |
CVE-2026-24296 | Windows Device Association Service | Windows Device Association Service Elevation of Privilege | Important | 7.0 |
CVE-2026-25170 | Role: Windows Hyper-V | Windows Hyper-V Elevation of Privilege | Important | 7.0 |
CVE-2026-25171 | Windows Authentication Methods | Windows Authentication Elevation of Privilege | Important | 7.0 |
CVE-2026-25178 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-25179 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-24288 | Windows Mobile Broadband | Windows Mobile Broadband Driver Remote Code Execution | Important | 6.8 |
CVE-2026-24297 | Windows Kerberos | Windows Kerberos Security Feature Bypass | Important | 6.5 |
CVE-2026-25168 | Microsoft Graphics Component | Windows Graphics Component Denial of Service | Important | 6.2 |
CVE-2026-25169 | Microsoft Graphics Component | Windows Graphics Component Denial of Service | Important | 6.2 |
CVE-2026-23656 | Windows App Installer | Windows App Installer Spoofing | Important | 5.9 |
CVE-2026-24282 | Push Message Routing Service | Push message Routing Service Elevation of Privilege | Important | 5.5 |
CVE-2026-25180 | Microsoft Graphics Component | Windows Graphics Component Information Disclosure | Important | 5.5 |
CVE-2026-25186 | Windows Accessibility Infrastructure (ATBroker.exe) | Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure | Important | 5.5 |
CVE-2026-26123 | Microsoft Authenticator | Microsoft Authenticator Information Disclosure | Important | 5.5 |
CVE-2026-25185 | Windows Shell Link Processing | Windows Shell Link Processing Spoofing | Important | 5.3 |
Published later in the month (19)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 19 Mar | CVE-2026-32169 | Azure Cloud Shell Elevation of Privilege | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-26137 | Microsoft Exchange Elevation of Privilege | Critical | Fixed by Microsoft |
| 5 Mar | CVE-2026-21536 | Microsoft Devices Pricing Program Remote Code Execution | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-32191 | Microsoft Bing Images Remote Code Execution | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-32194 | Microsoft Bing Images Remote Code Execution | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-23658 | Azure DevOps: msazure Elevation of Privilege | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-23659 | Azure Data Factory Information Disclosure | Critical | Fixed by Microsoft |
| 5 Mar | CVE-2026-26125 | Payment Orchestrator Service Elevation of Privilege | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-26138 | Microsoft Purview Elevation of Privilege | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-26139 | Microsoft Purview Elevation of Privilege | Critical | Fixed by Microsoft |
| 5 Mar | CVE-2026-23651 | Microsoft ACI Confidential Containers Elevation of Privilege | Critical | Fixed by Microsoft |
| 5 Mar | CVE-2026-26124 | Microsoft ACI Confidential Containers Elevation of Privilege | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-26120 | Microsoft Bing Tampering | Critical | Fixed by Microsoft |
| 5 Mar | CVE-2026-26122 | Microsoft ACI Confidential Containers Information Disclosure | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-26136 | Microsoft Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 19 Mar | CVE-2026-24299 | M365 Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 12 Mar | CVE-2026-26133 | M365 Copilot Information Disclosure | Important | Update |
| 13 Mar | CVE-2026-0385 | Microsoft Edge (Chromium-based) for Android Spoofing | Low | Update |
| 27 Mar | CVE-2026-32187 | Microsoft Edge (Chromium-based) Defense in Depth Vulnerability – Rejected | Low | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 7 hours ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.