• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

Microsoft Patch Tuesday, March 2026 Version – Krebs on Safety

Admin by Admin
March 11, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Microsoft Corp. at the moment pushed safety updates to repair a minimum of 77 vulnerabilities in its Home windows working programs and different software program. There are not any urgent “zero-day” flaws this month (in comparison with February’s 5 zero-day deal with), however as ordinary some patches might deserve extra speedy consideration from organizations utilizing Home windows. Listed below are a couple of highlights from this month’s Patch Tuesday.

Picture: Shutterstock, @nwz.

Two of the bugs Microsoft patched at the moment had been publicly disclosed beforehand. CVE-2026-21262 is a weak spot that enables an attacker to raise their privileges on SQL Server 2016 and later editions.

“This isn’t simply any elevation of privilege vulnerability, both; the advisory notes that a certified attacker can elevate privileges to sysadmin over a community,” Rapid7’s Adam Barnett stated. “The CVSS v3 base rating of 8.8 is slightly below the edge for vital severity, since low-level privileges are required. It will be a brave defender who shrugged and deferred the patches for this one.”

The opposite publicly disclosed flaw is CVE-2026-26127, a vulnerability in purposes working on .NET. Barnett stated the rapid impression of exploitation is probably going restricted to denial of service by triggering a crash, with the potential for different forms of assaults throughout a service reboot.

It will hardly be a correct Patch Tuesday with out a minimum of one vital Microsoft Workplace exploit, and this month doesn’t disappoint. CVE-2026-26113 and CVE-2026-26110 are each distant code execution flaws that may be triggered simply by viewing a booby-trapped message within the Preview Pane.

Satnam Narang at Tenable notes that simply over half (55%) of all Patch Tuesday CVEs this month are privilege escalation bugs, and of these, a half dozen had been rated “exploitation extra doubtless” — throughout Home windows Graphics Part, Home windows Accessibility Infrastructure, Home windows Kernel, Home windows SMB Server and Winlogon. These embody:

–CVE-2026-24291: Incorrect permission assignments inside the Home windows Accessibility Infrastructure to succeed in SYSTEM (CVSS 7.8)
–CVE-2026-24294: Improper authentication within the core SMB element (CVSS 7.8)
–CVE-2026-24289: Excessive-severity reminiscence corruption and race situation flaw (CVSS 7.8)
–CVE-2026-25187: Winlogon course of weak spot found by Google Venture Zero (CVSS 7.8).

Ben McCarthy, lead cyber safety engineer at Immersive, known as consideration to CVE-2026-21536, a vital distant code execution bug in a element known as the Microsoft Units Pricing Program. Microsoft has already resolved the difficulty on their finish, and fixing it requires no motion on the a part of Home windows customers. However McCarthy says it’s notable as one of many first vulnerabilities recognized by an AI agent and formally acknowledged with a CVE attributed to the Home windows working system. It was found by XBOW, a totally autonomous AI penetration testing agent.

XBOW has constantly ranked at or close to the highest of the Hacker One bug bounty leaderboard for the previous yr. McCarthy stated CVE-2026-21536 demonstrates how AI brokers can establish vital 9.8-rated vulnerabilities with out entry to supply code.

“Though Microsoft has already patched and mitigated the vulnerability, it highlights a shift towards AI-driven discovery of complicated vulnerabilities at growing pace,” McCarthy stated. “This improvement suggests AI-assisted vulnerability analysis will play a rising position within the safety panorama.”

Microsoft earlier supplied patches to deal with 9 browser vulnerabilities, which aren’t included within the Patch Tuesday rely above. As well as, Microsoft issued an important out-of-band (emergency) replace on March 2 for Home windows Server 2022 to deal with a certificates renewal difficulty with passwordless authentication expertise Home windows Howdy for Enterprise.

Individually, Adobe shipped updates to repair 80 vulnerabilities — a few of them vital in severity — in a wide range of merchandise, together with Acrobat and Adobe Commerce. Mozilla Firefox v. 148.0.2 resolves three excessive severity CVEs.

For an entire breakdown of all of the patches Microsoft launched at the moment, take a look at the SANS Web Storm Middle’s Patch Tuesday submit. Home windows enterprise admins who want to keep abreast of any information about problematic updates, AskWoody.com is at all times price a go to. Please be happy to drop a remark beneath should you expertise any points apply this month’s patches.

Tags: EditionKrebsMarchMicrosoftPatchSecurityTuesday
Admin

Admin

Next Post
an unobtrusive eye-level digital camera, improved battery, and plenty of frames, however some could really feel uncomfortable with a face-mounted digital camera (Jay Peters/The Verge)

Traders flee to Magnificent Seven shares because of the US-led conflict in Iran; tech is up 1.5% from February 27, the one S&P 500 sector to rise because the strikes (Monetary Instances)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Over 100,000 WordPress Websites Uncovered to Privilege Escalation through MCP AI Engine

Over 100,000 WordPress Websites Uncovered to Privilege Escalation through MCP AI Engine

June 19, 2025
Pastime mindset | Seth’s Weblog

Sorts of reckless | Seth’s Weblog

September 13, 2025

Trending.

10 tricks to begin getting ready! • Yoast

10 tricks to begin getting ready! • Yoast

July 21, 2025
AI-Assisted Menace Actor Compromises 600+ FortiGate Gadgets in 55 Nations

AI-Assisted Menace Actor Compromises 600+ FortiGate Gadgets in 55 Nations

February 23, 2026
Design Has By no means Been Extra Vital: Inside Shopify’s Acquisition of Molly

Design Has By no means Been Extra Vital: Inside Shopify’s Acquisition of Molly

September 8, 2025
Exporting a Material Simulation from Blender to an Interactive Three.js Scene

Exporting a Material Simulation from Blender to an Interactive Three.js Scene

August 20, 2025
Expedition 33 Guides, Codex, and Construct Planner

Expedition 33 Guides, Codex, and Construct Planner

April 26, 2025

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Overwatch’s Nier Automata Skins Value Extra Than Nier Automata

Overwatch’s Nier Automata Skins Value Extra Than Nier Automata

March 11, 2026
an unobtrusive eye-level digital camera, improved battery, and plenty of frames, however some could really feel uncomfortable with a face-mounted digital camera (Jay Peters/The Verge)

Traders flee to Magnificent Seven shares because of the US-led conflict in Iran; tech is up 1.5% from February 27, the one S&P 500 sector to rise because the strikes (Monetary Instances)

March 11, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved