Microsoft Patch Tuesday security updates for March 2026 fixed 84 bugs
好的,我现在需要帮用户总结这篇文章的内容。用户的要求是用中文,控制在100字以内,不需要特定的开头,直接写描述即可。 首先,我快速浏览文章内容。文章主要讲的是微软在2026年3月的补丁星期二更新中修复了84个漏洞。这些漏洞涉及多个产品,包括Windows、Office、Edge等。其中有8个被评级为Critical,其余为Important。两个漏洞已经被公开披露,但目前没有被利用的迹象。 接下来,我需要提取关键信息:时间(2026年3月)、修复的漏洞数量(84个)、涉及的产品范围、漏洞等级(8个Critical)、已公开但未被利用的情况。 然后,我要把这些信息浓缩到100字以内。要注意用词简洁,避免冗余。例如,“修复了84个漏洞”可以简化为“修复84个漏洞”。 最后,检查字数是否符合要求,并确保信息准确无误。确保没有遗漏重要细节,比如涉及的产品和漏洞等级。 总结起来,最终的描述应该包含时间、修复的漏洞数量、产品范围、漏洞等级以及已公开但未被利用的情况。 </think> 微软2026年3月补丁星期二更新修复了84个漏洞,涵盖Windows、Office等产品。其中8个为严重级别,其余为重要级别。两个漏洞已公开披露但未被利用。 2026-3-10 23:29:18 Author: securityaffairs.com(查看原文) 阅读量:7 收藏

Microsoft Patch Tuesday security updates for March 2026 fixed 84 bugs

Microsoft Patch Tuesday security updates for March 2026 addressed 84 vulnerabilities in its products. None of the flaws are known to be exploited so far.

Microsoft Patch Tuesday security updates for March 2026 addressed 84 vulnerabilities across its products. The IT giant addressed flaws across Windows, Office, Edge, Azure, SQL Server, Hyper-V, and ReFS. Including third-party and Chromium updates, the total reaches 94 vulnerabilities. Eight flaws are rated Critical and the rest Important. Two vulnerabilities, tracked as CVE-2026-26127 and CVE-2026-21262, were publicly disclosed, but none is known to be actively exploited.

Below are the descriptions of these flaws:

  • CVE-2026-26127 (CVSS score of 7.5) – .NET out-of-bounds read allows unauthenticated remote attackers to cause denial of service against .NET-based apps over the network.zh-tw.tenable+2
  • CVE-2026-21262 (CVSS score of 8.8) – Microsoft SQL Server elevation of privilege flaw letting an authenticated user escalate to full SQL sysadmin privileges on the database server.isc.sans+1

Other interesting flaws addressed by Microsoft are:

  • CVE-2026-21536 (CVSS score of 9.8) – allows remote attackers to execute arbitrary code on Microsoft Devices Pricing Program services over the network without privileges or user interaction, marking it the most severe flaw in Microsoft’s March 2026 Patch Tuesday.
  • CVE-2026-26110 (CVSS score of 8.4) – enables remote code execution in Microsoft Office through malicious files processed in the Preview Pane, potentially allowing zero-click exploitation when users simply view documents.

The full list of CVEs addressed by Microsoft Patch Tuesday security updates for March 2026 is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft)




文章来源: https://securityaffairs.com/189266/security/microsoft-patch-tuesday-security-updates-for-march-2026-fixed-84-bugs.html
如有侵权请联系:admin#unsafe.sh