Full Report
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities. [...]
Analysis Summary
# Vulnerability: Microsoft March 2026 Patch Tuesday (Cumulative Summary)
## CVE Details
- CVE ID: CVE-2026-21262, CVE-2026-26127, CVE-2026-26110, CVE-2026-26113, CVE-2026-26144 (among 79 total)
- CVSS Score: Varies - Up to "Critical"
- CWE: Includes Out-of-bounds Read, Improper Access Control, and others.
## Affected Systems
- Products: Microsoft Windows (11, Server), SQL Server, .NET, Microsoft Office (Excel, Word), Windows SMB Server, Win32K.
- Versions: Windows 11 (KB5079473 & KB5078883), Microsoft SQL Server, .NET, Microsoft Office 365/2021/2019.
- Configurations: Systems utilizing the Microsoft Copilot Agent mode (CVE-2026-26144) or Office Preview Pane (CVE-2026-26110/26113).
## Vulnerability Description
This patch cycle addresses 79 flaws. Key technical highlights include:
- **Publicly Disclosed Zero-days:** SQL Server Elevation of Privilege (Improper access control allowing SQLAdmin rights) and .NET Denial of Service (Out-of-bounds read over a network).
- **Critical RCEs:** Microsoft Office flaws that can be triggered via the **Preview Pane**, eliminating the need for a user to open the file.
- **Copilot Information Disclosure:** A flaw in Microsoft Excel that allows an attacker to force Copilot Agent mode to exfiltrate data via unintended network egress (Zero-click).
## Exploitation
- Status: 2 Publicly Disclosed (CVE-2026-21262, CVE-2026-26127); None currently exploited in the wild at time of report.
- Complexity: Low to Medium.
- Attack Vector: Network (majority), Local (Elevation of Privilege).
## Impact
- Confidentiality: High (Information disclosure via Copilot and Office).
- Integrity: High (Elevation of privilege to SQLAdmin and System levels).
- Availability: High (Denial of Service in .NET and Windows services).
## Remediation
### Patches
- Windows 11: Apply KB5079473 and KB5078883.
- SQL Server: Apply latest security servicing updates.
- Microsoft Office: Update to the March 2026 build via "Check for Updates."
### Workarounds
- Disable the Office Preview Pane to mitigate CVE-2026-26110 and CVE-2026-26113.
- Restrict network access to SQL Server instances to authorized users only.
## Detection
- **Indicators of Compromise:** Unusual network egress from Copilot-enabled applications or unauthorized elevation to SQLAdmin status.
- **Tools:** Use Microsoft Defender Vulnerability Management or standard WSUS/SCCM reporting to identify unpatched assets.
## References
- Microsoft Security Update Guide: hxxps[://]msrc[.]microsoft[.]com/update-guide/
- BleepingComputer News: hxxps[://]www[.]bleepingcomputer[.]com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/
- Windows 11 Cumulative Updates: hxxps[://]learn[.]microsoft[.]com/en-us/windows/release-health/