Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days
    Cybersecurity

    Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

    adminBy adminMarch 11, 2026No Comments4 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft on Tuesday released patches for a set of 84 new security vulnerabilities affecting various software components, including two that have been listed as publicly known.

    Of these, eight are rated Critical, and 76 are rated Important in severity. Forty-six of the patched vulnerabilities relate to privilege escalation, followed by 18 remote code execution, 10 information disclosure, four spoofing, four denial-of-service, and two security feature bypass flaws.

    The fixes are in addition to 10 vulnerabilities that have been addressed in its Chromium-based Edge browser since the release of the February 2026 Patch Tuesday update.

    The two publicly disclosed zero-days are CVE-2026-26127 (CVSS score: 7.5), a denial-of-service vulnerability in .NET, and CVE-2026-21262 (CVSS score: 8.8), an elevation of privilege vulnerability in SQL Server.

    The vulnerability with the highest CVSS score in this month’s update is a critical remote code execution flaw in the Microsoft Devices Pricing Program. CVE-2026-21536 (CVSS score: 9.8), per Microsoft, has been fully mitigated, and no action is required from users. Artificial intelligence (AI)-powered autonomous vulnerability discovery platform XBOW has been credited with discovering and reporting the issue.

    “This month, over half (55%) of all Patch Tuesday CVEs were privilege escalation bugs, and of those, six were rated exploitation more likely across Windows Graphics Component, Windows Accessibility Infrastructure, Windows Kernel, Windows SMB Server, and Winlogon,” Satnam Narang, senior staff research engineer at Tenable, said.

    “We know these bugs are typically used by threat actors as part of post-compromise activity, once they get onto systems through other means (social engineering, exploitation of another vulnerability).”

    The Winlogon privilege escalation flaw (CVE-2026-25187, CVSS score: 7.8), in particular, leverages improper link resolution to obtain SYSTEM privileges. Google Project Zero researcher James Forshaw has been acknowledged for reporting the vulnerability.

    “The flaw allows a locally authenticated attacker with low privileges to exploit a link-following condition in the Winlogon process and escalate to SYSTEM privileges,” Jacob Ashdown, cybersecurity engineer at Immersive, said. “The vulnerability requires no user interaction and has low attack complexity, making it a straightforward target once an attacker gains a foothold.”

    Another vulnerability of note is CVE-2026-26118 (CVSS score: 8.8), a server-side request forgery bug in the Azure Model Context Protocol (MCP) server that could allow an authorized attacker to elevate privileges over a network.

    “An attacker could exploit this issue by sending specially crafted input to an Azure Model Context Protocol (MCP) Server tool that accepts user‑provided parameters,” Microsoft said.

    “If the attacker can interact with the MCP‑backed agent, they can submit a malicious URL in place of a normal Azure resource identifier. The MCP Server then sends an outbound request to that URL and, in doing so, may include its managed identity token. This allows the attacker to capture that token without requiring administrative access.”

    Successful exploitation of the vulnerability could permit an attacker to obtain the permissions associated with the MCP Server’s managed identity. The attacker could then leverage this behavior to access or perform actions on any resources that the managed identity is authorized to reach.

    Among the Critical-severity bugs resolved by Microsoft is an information disclosure flaw in Excel. Tracked as CVE-2026-26144 (CVSS score of 7.5), it has been described as a case of cross-site scripting that occurs as a result of improper neutralization of input during web page generation.

    The Windows maker said an attacker who exploited the shortcoming could potentially cause Copilot Agent mode to exfiltrate data as part of a zero-click attack.

    “Information disclosure vulnerabilities are especially dangerous in corporate environments where Excel files often contain financial data, intellectual property, or operational records,” Alex Vovk, CEO and co-founder of Action1, said in a statement.

    “If exploited, attackers could silently extract confidential information from internal systems without triggering obvious alerts. Organizations using AI-assisted productivity features may face increased exposure, as automated agents could unintentionally transmit sensitive data outside corporate boundaries.”

    The patches come as Microsoft said it’s changing the default behavior of Windows Autopatch by enabling hotpatch security updates to help secure devices at a faster pace.

    “This change in default behavior comes to all eligible devices in Microsoft Intune and those accessing the service via Microsoft Graph API starting with the May 2026 Windows security update,” Redmond said. “Applying security fixes without waiting for a restart can get organizations to 90% compliance in half the time, while you remain in control.”

    Flaws including March Microsoft Patch Patches public Tuesday ZeroDays
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWordPress Releases A Security Update Followed By A Bugfix
    Next Article ColorOS Internet Browser 45.13.9.1 by HeyTap
    admin
    • Website

    Related Posts

    Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

    March 11, 2026

    Fortanix helps enterprises build resilience with multi-sourced quantum entropy

    March 11, 2026

    Meta adds new WhatsApp, Facebook, and Messenger anti-scam tools

    March 11, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Here’s your best look at Google Pixel’s new Transit mode

    March 11, 2026

    Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

    March 11, 2026

    How Amy Aitman Breaks Down the “Three-Legged Stool”: 3 Channels, 1 Visibility Goal

    March 11, 2026

    5 Things I Learned About The Future Of Search From Liz Reid’s Latest Interview

    March 11, 2026
    Categories
    • Blogging (37)
    • Cybersecurity (718)
    • Privacy & Online Earning (107)
    • SEO & Digital Marketing (451)
    • Tech Tools & Mobile / Apps (886)
    • WiFi / Internet & Networking (118)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Here’s your best look at Google Pixel’s new Transit mode

    March 11, 2026

    Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

    March 11, 2026

    How Amy Aitman Breaks Down the “Three-Legged Stool”: 3 Channels, 1 Visibility Goal

    March 11, 2026
    Most Popular
    • Here’s your best look at Google Pixel’s new Transit mode
    • Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
    • How Amy Aitman Breaks Down the “Three-Legged Stool”: 3 Channels, 1 Visibility Goal
    • 5 Things I Learned About The Future Of Search From Liz Reid’s Latest Interview
    • This smart TV brand crossed a big line with its absurd ad antics
    • Fortanix helps enterprises build resilience with multi-sourced quantum entropy
    • The simple genius behind this long-forgotten Google Chrome ad
    • Five Hacks Every Fitness Watch User Should Know
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.