On-demand webinar: Building a secure and employee-centric digital workplace

WATCH NOW

Microsoft Patch Tuesday March 2026 - Summary

148

Patches

88

Vulnerabilities

16

Articles

6

Impacts

CVE Index for March 2026 Patch Tuesday Updates

Vulnerable ComponentImpactCVE ID
Microsoft Excel Information Disclosure CVE-2026-26144
Microsoft Office Remote Code Execution CVE-2026-26110
Microsoft Office Remote Code Execution CVE-2026-26113
Vulnerable ComponentImpactCVE ID
.NET Denial of Service CVE-2026-26127
SQL Server Elevation of Privilege CVE-2026-21262
CVE IDSeverityImpact
CVE-2026-26141 Important Elevation of Privilege
CVE-2026-26123 Important Information Disclosure
CVE-2026-26117 Important Elevation of Privilege
CVE-2026-23674 Important Security Feature Bypass
CVE-2026-26132 Important Elevation of Privilege
CVE-2026-26128 Important Elevation of Privilege
CVE-2026-23656 Important Spoofing
CVE-2026-26030 Important Remote Code Execution
CVE-2026-26111 Important Remote Code Execution
CVE-2026-25190 Important Remote Code Execution
CVE-2026-25189 Important Elevation of Privilege
CVE-2026-25188 Important Elevation of Privilege
CVE-2026-25186 Important Information Disclosure
CVE-2026-25185 Important Spoofing
CVE-2026-25181 Important Information Disclosure
CVE-2026-25180 Important Information Disclosure
CVE-2026-25179 Important Elevation of Privilege
CVE-2026-25178 Important Elevation of Privilege
CVE-2026-25176 Important Elevation of Privilege
CVE-2026-25175 Important Elevation of Privilege
CVE-2026-25174 Important Elevation of Privilege
CVE-2026-25173 Important Remote Code Execution
CVE-2026-25172 Important Remote Code Execution
CVE-2026-25171 Important Elevation of Privilege
CVE-2026-25170 Important Elevation of Privilege
CVE-2026-25169 Important Denial of Service
CVE-2026-25168 Important Denial of Service
CVE-2026-25167 Important Elevation of Privilege
CVE-2026-25166 Important Remote Code Execution
CVE-2026-25165 Important Elevation of Privilege
CVE-2026-24297 Important Security Feature Bypass
CVE-2026-24296 Important Elevation of Privilege
CVE-2026-24295 Important Elevation of Privilege
CVE-2026-24294 Important Elevation of Privilege
CVE-2026-24293 Important Elevation of Privilege
CVE-2026-24292 Important Elevation of Privilege
CVE-2026-24291 Important Elevation of Privilege
CVE-2026-24290 Important Elevation of Privilege
CVE-2026-24289 Important Elevation of Privilege
CVE-2026-24288 Important Remote Code Execution
CVE-2026-24287 Important Elevation of Privilege
CVE-2026-24285 Important Elevation of Privilege
CVE-2026-24283 Important Elevation of Privilege
CVE-2026-23673 Important Elevation of Privilege
CVE-2026-23672 Important Elevation of Privilege
CVE-2026-23671 Important Elevation of Privilege
CVE-2026-23669 Important Remote Code Execution
CVE-2026-23668 Important Elevation of Privilege
CVE-2026-23660 Important Elevation of Privilege
CVE IDSeverityImpact
CVE-2026-26109 Important Remote Code Execution
CVE-2026-26108 Important Remote Code Execution
CVE-2026-26107 Important Remote Code Execution
CVE-2026-26106 Important Remote Code Execution
CVE-2026-26134 Important Elevation of Privilege
CVE-2026-26116 Important Elevation of Privilege
CVE-2026-26115 Important Elevation of Privilege
CVE-2026-26114 Important Remote Code Execution
CVE-2026-26112 Important Remote Code Execution
CVE-2026-26105 Important Spoofing
CVE IDSeverityImpact
CVE-2026-26118 Important Elevation of Privilege
CVE-2026-23665 Important Elevation of Privilege
CVE-2026-23662 Important Information Disclosure
CVE-2026-23661 Important Information Disclosure
CVE-2026-26148 Important Elevation of Privilege
CVE-2026-26121 Important Spoofing
CVE-2026-23664 Important Information Disclosure
Vulnerable ComponentCVE IDSeverityImpact
Winlogon CVE-2026-25187 Important Elevation of Privilege
GitHub: Zero Shot SCFoundation CVE-2026-23654 Important Remote Code Execution
ASP.NET Core CVE-2026-26130 Important Denial of Service
System Center Operations Manager (SCOM) CVE-2026-20967 Important Elevation of Privilege
.NET CVE-2026-26131 Important Elevation of Privilege
Active Directory Domain Services CVE-2026-25177 Important Elevation of Privilege
Broadcast DVR CVE-2026-23667 Important Elevation of Privilege
Push message Routing Service Elevation of Privilege CVE-2026-24282 Important Information Disclosure

Previous Patch Tuesday Updates and Fixes

Microsoft Windows Patch Tuesday - Overview

What is Patch Tuesday?

Patch Tuesday or Update Tuesday is the common name for the second Tuesday of every month when Microsoft releases security updates for its operating system and other software. Coinciding with the Patch Tuesday, several other vendors such as Oracle, Mozilla, Adobe, and many others roll out updates for the third-party applications.

When is Patch Tuesday?

Patch Tuesday falls on the second Tuesday of each month. The upcoming Patch Tuesday is on Apr 14, 2026.

What is patching and why is it important?

Patches are nothing but pieces of software code that are written to fix a bug in a software application, that might lead to a vulnerability. Such vulnerabilities in any application are loop holes for attackers to get their hands on business critical data and information. So it is highly crucial to keep all the applications in a network updated to its latest versions. Updating applications in mobile phones and laptops also work in the same manner by preventing theft of personal data, through security flaws.

What kind of patch updates are released during Patch Tuesday?

Predominantly security patch updates of varying severity like Critical, Important, Moderate & Low are labeled and released. Effective Windows patch management involves prioritizing these based on severity, automating deployment, and ensuring rollback or compatibility testing. It is always a best practice to prioritize your patching based on the severity level mentioned.

What are CVE IDs?

CVE ID - Common Vulnerabilities and Exposure ID is a format in which each vulnerability is disclosed and cataloged in the National Vulnerability Database (NVD). You can look up for a detailed explanation of each vulnerability in the NVD with the help of CVE ID. In Patch Manager Plus you can make use of these CVE IDs to fetch the appropriate patches to deploy. You can find the CVE IDs here.

How to register for ManageEngine's Free Patch Tuesday webinar?

The upcoming Free Patch Tuesday webinar by ManageEngine is scheduled on -. You can make your registrations here.

Where can I find more details about individual bulletins?

Each CVE ID listed in the CVE Index section has been linked to its security advisory.