By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days
Computing

Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

News Room
Last updated: 2026/03/11 at 5:30 AM
News Room Published 11 March 2026
Share
Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days
SHARE

Microsoft on Tuesday released patches for a set of 84 new security vulnerabilities affecting various software components, including two that have been listed as publicly known.

Of these, eight are rated Critical, and 76 are rated Important in severity. Forty-six of the patched vulnerabilities relate to privilege escalation, followed by 18 remote code execution, 10 information disclosure, four spoofing, four denial-of-service, and two security feature bypass flaws.

The fixes are in addition to 10 vulnerabilities that have been addressed in its Chromium-based Edge browser since the release of the February 2026 Patch Tuesday update.

The two publicly disclosed zero-days are CVE-2026-26127 (CVSS score: 7.5), a denial-of-service vulnerability in .NET, and CVE-2026-21262 (CVSS score: 8.8), an elevation of privilege vulnerability in SQL Server.

The vulnerability with the highest CVSS score in this month’s update is a critical remote code execution flaw in the Microsoft Devices Pricing Program. CVE-2026-21536 (CVSS score: 9.8), per Microsoft, has been fully mitigated, and no action is required from users. Artificial intelligence (AI)-powered autonomous vulnerability discovery platform XBOW has been credited with discovering and reporting the issue.

“This month, over half (55%) of all Patch Tuesday CVEs were privilege escalation bugs, and of those, six were rated exploitation more likely across Windows Graphics Component, Windows Accessibility Infrastructure, Windows Kernel, Windows SMB Server, and Winlogon,” Satnam Narang, senior staff research engineer at Tenable, said.

“We know these bugs are typically used by threat actors as part of post-compromise activity, once they get onto systems through other means (social engineering, exploitation of another vulnerability).”

The Winlogon privilege escalation flaw (CVE-2026-25187, CVSS score: 7.8), in particular, leverages improper link resolution to obtain SYSTEM privileges. Google Project Zero researcher James Forshaw has been acknowledged for reporting the vulnerability.

“The flaw allows a locally authenticated attacker with low privileges to exploit a link-following condition in the Winlogon process and escalate to SYSTEM privileges,” Jacob Ashdown, cybersecurity engineer at Immersive, said. “The vulnerability requires no user interaction and has low attack complexity, making it a straightforward target once an attacker gains a foothold.”

Another vulnerability of note is CVE-2026-26118 (CVSS score: 8.8), a server-side request forgery bug in the Azure Model Context Protocol (MCP) server that could allow an authorized attacker to elevate privileges over a network.

“An attacker could exploit this issue by sending specially crafted input to an Azure Model Context Protocol (MCP) Server tool that accepts user‑provided parameters,” Microsoft said.

“If the attacker can interact with the MCP‑backed agent, they can submit a malicious URL in place of a normal Azure resource identifier. The MCP Server then sends an outbound request to that URL and, in doing so, may include its managed identity token. This allows the attacker to capture that token without requiring administrative access.”

Successful exploitation of the vulnerability could permit an attacker to obtain the permissions associated with the MCP Server’s managed identity. The attacker could then leverage this behavior to access or perform actions on any resources that the managed identity is authorized to reach.

Among the Critical-severity bugs resolved by Microsoft is an information disclosure flaw in Excel. Tracked as CVE-2026-26144 (CVSS score of 7.5), it has been described as a case of cross-site scripting that occurs as a result of improper neutralization of input during web page generation.

The Windows maker said an attacker who exploited the shortcoming could potentially cause Copilot Agent mode to exfiltrate data as part of a zero-click attack.

“Information disclosure vulnerabilities are especially dangerous in corporate environments where Excel files often contain financial data, intellectual property, or operational records,” Alex Vovk, CEO and co-founder of Action1, said in a statement.

“If exploited, attackers could silently extract confidential information from internal systems without triggering obvious alerts. Organizations using AI-assisted productivity features may face increased exposure, as automated agents could unintentionally transmit sensitive data outside corporate boundaries.”

The patches come as Microsoft said it’s changing the default behavior of Windows Autopatch by enabling hotpatch security updates to help secure devices at a faster pace.

“This change in default behavior comes to all eligible devices in Microsoft Intune and those accessing the service via Microsoft Graph API starting with the May 2026 Windows security update,” Redmond said. “Applying security fixes without waiting for a restart can get organizations to 90% compliance in half the time, while you remain in control.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Legora raises 0M to fuel U.S. expansion of AI agents that automate legal work –  News Legora raises $550M to fuel U.S. expansion of AI agents that automate legal work – News
Next Article Wrike Review: Effective and Flexible (But Pricey) Project Management Wrike Review: Effective and Flexible (But Pricey) Project Management
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Starbucks denies reports it plans to fully exit China
Starbucks denies reports it plans to fully exit China
Computing
Here’s why M5 MacBook Pro is worth buying now, even with an impending redesign – 9to5Mac
Here’s why M5 MacBook Pro is worth buying now, even with an impending redesign – 9to5Mac
News
These Are The Best Desktop PCs Of 2026, According To Consumer Reports – BGR
These Are The Best Desktop PCs Of 2026, According To Consumer Reports – BGR
News
TikTok Marketing: The Ultimate Guide (2022) |
TikTok Marketing: The Ultimate Guide (2022) |
Computing

You Might also Like

Starbucks denies reports it plans to fully exit China
Computing

Starbucks denies reports it plans to fully exit China

1 Min Read
TikTok Marketing: The Ultimate Guide (2022) |
Computing

TikTok Marketing: The Ultimate Guide (2022) |

8 Min Read
The HackerNoon Newsletter: Want to Have Successful OpenTelemetry Projects? Implement This One Tip (4/4/2026) | HackerNoon
Computing

The HackerNoon Newsletter: Want to Have Successful OpenTelemetry Projects? Implement This One Tip (4/4/2026) | HackerNoon

1 Min Read
NIO’s mini EV firefly now costs only ,128 with battery leasing program · TechNode
Computing

NIO’s mini EV firefly now costs only $11,128 with battery leasing program · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?