March 2026 Patch Tuesday — 83 CVEs, 2 Zero-Days
March 2026 Patch Tuesday is the heaviest of 2026 so far. Here's what you need to know.
VULNERABILITIES COVERED:
SQL Server Zero-Day — CVSS 8.8 (CVE-2026-21262) — Privilege escalation to sysadmin
.NET Denial of Service — CVSS 7.5 (CVE-2026-26127) — Out-of-bounds read, publicly disclosed
Microsoft Office Pointer Dereference — CVSS 7.8 (CVE-2026-21263) — Local code execution
Word OLE + Mark-of-the-Web Bypass — CVSS 8.1 — Active exploitation
Two actively exploited zero-days patched
REMEDIATION:
Patch SQL Server immediately
Update .NET runtimes
Update Office to latest version
Audit Mark-of-the-Web configurations
Monitor for active exploitation
Zero-Day is Today.
#CVE #Cybersecurity #PatchTuesday #ZeroDay #InfoSec #SudoDylan #Microsoft #SQLServer #CVEAlert