Claude is having a major outage. Status board · Discuss Claude

Patch Tuesday: March 2026

Each month's Microsoft security updates: what to patch first, the Critical fixes, and what CISA says attackers are exploiting.

How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.

Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)

March 2026 Patch Tuesday: Microsoft fixed 78 vulnerabilities, 3 of them Critical. None was known to be exploited on the day. Released Tue 10 Mar 2026.

  • 78vulnerabilities fixed
  • 3Critical
  • 0exploited before the fix
  • 2publicly disclosed
  • 0now on CISA KEV

By type: 43 elevation of privilege, 16 remote code execution, 9 information disclosure, 4 spoofing, 4 denial of service, 2 security feature bypass.

Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.

Patch these first

Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.

CVEWhatSeverityCVSSWhy first
CVE-2026-21262Microsoft SQL Server Elevation of PrivilegeImportant8.8Publicly disclosed
CVE-2026-26127.NET Denial of ServiceImportant7.5Publicly disclosed

Critical (3)

Microsoft’s top rating: usually code execution with little or no user action.

CVEWhatImpactCVSS
CVE-2026-26110Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-26113Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-26144Microsoft Excel Information DisclosureInformation Disclosure7.5

Added to CISA KEV in March 2026 (26)

Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.

CVEVendor and productWhatAddedFederal deadlineRansomware
CVE-2026-3055Citrix NetScalerOut-of-Bounds Read30 Mar2 Apr 2026
CVE-2025-53521F5 BIG-IPStack-Based Buffer Overflow27 Mar30 Mar 2026
CVE-2026-33634Aquasecurity TrivyEmbedded Malicious Code26 Mar9 Apr 2026
CVE-2026-33017Langflow LangflowLangflow Code Injection25 Mar8 Apr 2026
CVE-2025-31277Apple Multiple ProductsBuffer Overflow20 Mar3 Apr 2026
CVE-2025-32432Craft CMS Craft CMSCraft CMS Code Injection20 Mar3 Apr 2026
CVE-2025-43510Apple Multiple ProductsImproper Locking20 Mar3 Apr 2026
CVE-2025-43520Apple Multiple ProductsClassic Buffer Overflow20 Mar3 Apr 2026
CVE-2025-54068Laravel LivewireCode Injection20 Mar3 Apr 2026
CVE-2026-20131Cisco Secure Firewall Management Center (FMC)Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data19 Mar22 Mar 2026Known
CVE-2025-66376Synacor Zimbra Collaboration Suite (ZCS)Cross-Site Scripting18 Mar1 Apr 2026
CVE-2026-20963Microsoft SharePointDeserialization of Untrusted Data18 Mar21 Mar 2026
CVE-2025-47813Wing FTP Server Wing FTP ServerWing FTP Server Information Disclosure16 Mar30 Mar 2026
CVE-2026-3909Google SkiaOut-of-Bounds Write13 Mar27 Mar 2026
CVE-2026-3910Google Chromium V8Improper Restriction of Operations Within the Bounds of a Memory Buffer13 Mar27 Mar 2026
CVE-2025-68613n8n n8nn8n Improper Control of Dynamically-Managed Code Resources11 Mar25 Mar 2026
CVE-2021-22054Omnissa Workspace One UEMOmnissa Workspace ONE Server-Side Request Forgery9 Mar23 Mar 2026
CVE-2025-26399SolarWinds Web Help DeskDeserialization of Untrusted Data9 Mar12 Mar 2026Known
CVE-2026-1603Ivanti Endpoint Manager (EPM)Ivanti Endpoint Manager (EPM) Authentication Bypass9 Mar23 Mar 2026
CVE-2017-7921Hikvision Multiple ProductsImproper Authentication5 Mar26 Mar 2026
CVE-2021-22681Rockwell Multiple ProductsInsufficient Protected Credentials5 Mar26 Mar 2026
CVE-2021-30952Apple Multiple ProductsInteger Overflow or Wraparound5 Mar26 Mar 2026
CVE-2023-41974Apple iOS and iPadOSUse-After-Free5 Mar26 Mar 2026
CVE-2023-43000Apple Multiple ProductsApple Multiple products Use-After-Free5 Mar26 Mar 2026
CVE-2026-21385Qualcomm Multiple ChipsetsMemory Corruption3 Mar24 Mar 2026
CVE-2026-22719Broadcom VMware Aria OperationsCommand Injection3 Mar24 Mar 2026

All 78 fixes

Show the full list, with a filter
CVEProductWhatSeverityCVSS
CVE-2026-26110Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-26113Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-26144Microsoft Office ExcelMicrosoft Excel Information DisclosureCritical7.5
CVE-2026-20967System Center Operations ManagerSystem Center Operations Manager (SCOM) Elevation of PrivilegeImportant8.8
CVE-2026-21262SQL ServerMicrosoft SQL Server Elevation of PrivilegeImportant8.8
CVE-2026-23654GitHub Repo: zero-shot-scfoundationGitHub: Zero Shot SCFoundation Remote Code ExecutionImportant8.8
CVE-2026-23669RPC RuntimeRPC Runtime Library Remote Code ExecutionImportant8.8
CVE-2026-24283Windows File ServerMultiple UNC Provider Kernel Driver Elevation of PrivilegeImportant8.8
CVE-2026-25177Active Directory Domain ServicesActive Directory Domain Services Elevation of PrivilegeImportant8.8
CVE-2026-25188Windows Telephony ServiceWindows Telephony Service Elevation of PrivilegeImportant8.8
CVE-2026-26106Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant8.8
CVE-2026-26114Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant8.8
CVE-2026-26115SQL ServerSQL Server Elevation of PrivilegeImportant8.8
CVE-2026-26116SQL ServerSQL Server Elevation of PrivilegeImportant8.8
CVE-2026-26118Azure MCP ServerAzure MCP Server Tools Elevation of PrivilegeImportant8.8
CVE-2026-26109Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant8.4
CVE-2026-26105Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant8.1
CVE-2026-26148Azure Entra IDMicrosoft Azure AD SSH Login extension for Linux Elevation of PrivilegeImportant8.1
CVE-2026-25172Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code ExecutionImportant8.0
CVE-2026-25173Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code ExecutionImportant8.0
CVE-2026-26111Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code ExecutionImportant8.0
CVE-2026-23660Azure Portal Windows Admin CenterWindows Admin Center in Azure Portal Elevation of PrivilegeImportant7.8
CVE-2026-23665Azure Linux Virtual MachinesLinux Azure Diagnostic extension (LAD) Elevation of PrivilegeImportant7.8
CVE-2026-23672Windows Universal Disk Format File System Driver (UDFS)Windows Universal Disk Format File System Driver (UDFS) Elevation of PrivilegeImportant7.8
CVE-2026-23673Windows Resilient File System (ReFS)Windows Resilient File System (ReFS) Elevation of PrivilegeImportant7.8
CVE-2026-24287Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-24289Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-24290Windows Projected File SystemWindows Projected File System Elevation of PrivilegeImportant7.8
CVE-2026-24291Windows Accessibility Infrastructure (ATBroker.exe)Windows Accessibility Infrastructure (ATBroker.exe) Elevation of PrivilegeImportant7.8
CVE-2026-24292Connected Devices Platform Service (Cdpsvc)Windows Connected Devices Platform Service Elevation of PrivilegeImportant7.8
CVE-2026-24293Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-24294Windows SMB ServerWindows SMB Server Elevation of PrivilegeImportant7.8
CVE-2026-25165Windows Performance CountersPerformance Counters for Windows Elevation of PrivilegeImportant7.8
CVE-2026-25166Windows System Image ManagerWindows System Image Manager Assessment and Deployment Kit (ADK) Remote Code ExecutionImportant7.8
CVE-2026-25174Windows Extensible File AllocationWindows Extensible File Allocation Table Elevation of PrivilegeImportant7.8
CVE-2026-25175Windows NTFSWindows NTFS Elevation of PrivilegeImportant7.8
CVE-2026-25176Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-25187WinlogonWinlogon Elevation of PrivilegeImportant7.8
CVE-2026-25189Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-25190Windows GDIWindows GDI Remote Code ExecutionImportant7.8
CVE-2026-26107Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-26108Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-26112Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-26117Azure Windows Virtual Machine AgentArc Enabled Servers – Azure Connected Machine Agent Elevation of PrivilegeImportant7.8
CVE-2026-26128Windows SMB ServerWindows SMB Server Elevation of PrivilegeImportant7.8
CVE-2026-26131.NET.NET Elevation of PrivilegeImportant7.8
CVE-2026-26132Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-26134Microsoft OfficeMicrosoft Office Elevation of PrivilegeImportant7.8
CVE-2026-26141Azure ArcHybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of PrivilegeImportant7.8
CVE-2026-23661Azure IoT ExplorerAzure IoT Explorer Information DisclosureImportant7.5
CVE-2026-23662Azure IoT ExplorerAzure IoT Explorer Information DisclosureImportant7.5
CVE-2026-23664Azure IoT ExplorerAzure IoT Explorer Information DisclosureImportant7.5
CVE-2026-23674Windows MapUrlToZoneMapUrlToZone Security Feature BypassImportant7.5
CVE-2026-25181Windows GDI+GDI+ Information DisclosureImportant7.5
CVE-2026-26121Azure IoT ExplorerAzure IOT Explorer SpoofingImportant7.5
CVE-2026-26127.NET.NET Denial of ServiceImportant7.5
CVE-2026-26130ASP.NET CoreASP.NET Core Denial of ServiceImportant7.5
CVE-2026-25167Windows Brokering File SystemMicrosoft Brokering File System Elevation of PrivilegeImportant7.4
CVE-2026-23667Broadcast DVRBroadcast DVR Elevation of PrivilegeImportant7.0
CVE-2026-23668Microsoft Graphics ComponentWindows Graphics Component Elevation of PrivilegeImportant7.0
CVE-2026-23671Windows Bluetooth RFCOM Protocol DriverWindows Bluetooth RFCOM Protocol Driver Elevation of PrivilegeImportant7.0
CVE-2026-24285Windows Win32KWin32k Elevation of PrivilegeImportant7.0
CVE-2026-24295Windows Device Association ServiceWindows Device Association Service Elevation of PrivilegeImportant7.0
CVE-2026-24296Windows Device Association ServiceWindows Device Association Service Elevation of PrivilegeImportant7.0
CVE-2026-25170Role: Windows Hyper-VWindows Hyper-V Elevation of PrivilegeImportant7.0
CVE-2026-25171Windows Authentication MethodsWindows Authentication Elevation of PrivilegeImportant7.0
CVE-2026-25178Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-25179Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-24288Windows Mobile BroadbandWindows Mobile Broadband Driver Remote Code ExecutionImportant6.8
CVE-2026-24297Windows KerberosWindows Kerberos Security Feature BypassImportant6.5
CVE-2026-25168Microsoft Graphics ComponentWindows Graphics Component Denial of ServiceImportant6.2
CVE-2026-25169Microsoft Graphics ComponentWindows Graphics Component Denial of ServiceImportant6.2
CVE-2026-23656Windows App InstallerWindows App Installer SpoofingImportant5.9
CVE-2026-24282Push Message Routing ServicePush message Routing Service Elevation of PrivilegeImportant5.5
CVE-2026-25180Microsoft Graphics ComponentWindows Graphics Component Information DisclosureImportant5.5
CVE-2026-25186Windows Accessibility Infrastructure (ATBroker.exe)Windows Accessibility Infrastructure (ATBroker.exe) Information DisclosureImportant5.5
CVE-2026-26123Microsoft AuthenticatorMicrosoft Authenticator Information DisclosureImportant5.5
CVE-2026-25185Windows Shell Link ProcessingWindows Shell Link Processing SpoofingImportant5.3

Published later in the month (19)

Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.

DateCVEWhatSeverityAction
19 MarCVE-2026-32169Azure Cloud Shell Elevation of PrivilegeCriticalFixed by Microsoft
19 MarCVE-2026-26137Microsoft Exchange Elevation of PrivilegeCriticalFixed by Microsoft
5 MarCVE-2026-21536Microsoft Devices Pricing Program Remote Code ExecutionCriticalFixed by Microsoft
19 MarCVE-2026-32191Microsoft Bing Images Remote Code ExecutionCriticalFixed by Microsoft
19 MarCVE-2026-32194Microsoft Bing Images Remote Code ExecutionCriticalFixed by Microsoft
19 MarCVE-2026-23658Azure DevOps: msazure Elevation of PrivilegeCriticalFixed by Microsoft
19 MarCVE-2026-23659Azure Data Factory Information DisclosureCriticalFixed by Microsoft
5 MarCVE-2026-26125Payment Orchestrator Service Elevation of PrivilegeCriticalFixed by Microsoft
19 MarCVE-2026-26138Microsoft Purview Elevation of PrivilegeCriticalFixed by Microsoft
19 MarCVE-2026-26139Microsoft Purview Elevation of PrivilegeCriticalFixed by Microsoft
5 MarCVE-2026-23651Microsoft ACI Confidential Containers Elevation of PrivilegeCriticalFixed by Microsoft
5 MarCVE-2026-26124Microsoft ACI Confidential Containers Elevation of PrivilegeCriticalFixed by Microsoft
19 MarCVE-2026-26120Microsoft Bing TamperingCriticalFixed by Microsoft
5 MarCVE-2026-26122Microsoft ACI Confidential Containers Information DisclosureCriticalFixed by Microsoft
19 MarCVE-2026-26136Microsoft Copilot Information DisclosureCriticalFixed by Microsoft
19 MarCVE-2026-24299M365 Copilot Information DisclosureCriticalFixed by Microsoft
12 MarCVE-2026-26133M365 Copilot Information DisclosureImportantUpdate
13 MarCVE-2026-0385Microsoft Edge (Chromium-based) for Android SpoofingLowUpdate
27 MarCVE-2026-32187Microsoft Edge (Chromium-based) Defense in Depth Vulnerability – RejectedLowUpdate

From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 7 hours ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.

← All tools