TLP:CLEAR
Microsoft March 2026 Threat & Deployment BriefNo Active Exploitation, Prioritise Cycle, Cloud-Fixed 9.8

No exploited flaws and no customer-actionable 9.8 this month — deploy the Windows client and server cumulative on the normal 14-day cycle for six 'exploitation more likely' kernel, SMB and Winlogon elevation bugs. The single CVSS-9.8 is a cloud service Microsoft already fixed server-side.

Release
Microsoft 2026-03-10
CVEs
77–84 (by counter)
KEV read
2026-07-17
Report
ITS-EXV-2026-0310

This is a prioritise month, not an act month — and that is the finding. Every counter agrees no March CVE was exploited in the wild or is in CISA KEV. There is no evidence-lane emergency and nothing reaches the structural act gate. The Windows cumulative ships on the normal 14-day cadence; treat the calm as real, not as something to manufacture urgency around.

The Windows cumulative still leads, for six 'exploitation more likely' elevation bugs. Tenable flags six EoP flaws Microsoft rates more likely to be exploited — two in the Windows Kernel (CVE-2026-24289, CVE-2026-26132), plus SMB Server (CVE-2026-24294), Winlogon (CVE-2026-25187), Graphics (CVE-2026-23668) and Accessibility (CVE-2026-24291). None is exploited today; the rating is a forecast, and it is why this cumulative is a 14-day prioritise rather than a 30-day track.

Two flaws were publicly disclosed but not exploited. CVE-2026-21262 is a SQL Server elevation-of-privilege bug (8.8) that hands an authenticated user sysadmin over the network, credited to Erland Sommarskog; CVE-2026-26127 is a .NET denial-of-service (7.5). Public disclosure raises the odds that a technique circulates, so both are tracked deliberately — but neither is under attack.

The month's only CVSS-9.8 needs no action from you. CVE-2026-21536 in the Microsoft Devices Pricing Program is an unauthenticated cloud RCE that Microsoft patched server-side — there is no package to deploy. This is exactly why the narrower counters (Rapid7, BleepingComputer) report 'no 9.8' and even 'no Critical': they scope out cloud-side fixes. Do not let a 9.8 headline pull an on-prem change window it does not require.

The Office criticals are Preview-Pane RCEs, and they are track, not act. CVE-2026-26110 and CVE-2026-26113 are Office remote-code-execution flaws scored 8.4, one reachable through the Preview Pane. Office is neither exposed technology nor core infrastructure and neither flaw is exploited, so they ship on the normal cycle — with the Preview-Pane vector noted as the one caveat.

The worklist

1

Windows client and server monthly security update

Per-product servicing — see table
PRIORITISE
≤14 days

Why now. Not urgently. No flaw in this cumulative is exploited or in KEV, so it does not qualify for the evidence lane, and every notable flaw is a local-vector elevation of privilege that fails the structural impact gate — so it is Prioritise, not Act. What keeps it ahead of a 30-day track is that six of the EoPs (two in the Kernel, plus SMB Server, Winlogon, Graphics and Accessibility) carry Microsoft's 'exploitation more likely' rating: these are the classic second stage of a local intrusion, so closing them inside two weeks shortens the window in which a foothold becomes SYSTEM.

ProductPackageCarries
Windows 11 25H2 / 24H2KB5079473CVE-2026-24289, CVE-2026-24294, CVE-2026-25187
Windows 11 23H2KB5078883CVE-2026-24289, CVE-2026-24294, CVE-2026-25187
Windows 10 22H2 (ESU)KB5078885CVE-2026-24289, CVE-2026-24294, CVE-2026-25187
Windows Server 2025KB5078740CVE-2026-24289, CVE-2026-24294, CVE-2026-25187
Windows Server 2022KB5078766CVE-2026-24289, CVE-2026-24294, CVE-2026-25187
Windows Server 2019KB5078752CVE-2026-24289, CVE-2026-24294
Windows Server 2016KB5078938CVE-2026-24289, CVE-2026-24294

Also inside: The Kernel pair is CVE-2026-24289 and CVE-2026-26132; the other 'more likely' EoPs are CVE-2026-23668 (Graphics Component) and CVE-2026-24291 (Accessibility Infrastructure). The same servicing stack also ships the publicly-disclosed .NET denial-of-service CVE-2026-26127 (7.5) on servers that run affected .NET runtimes.

Then. Deploy the per-product package for your build from the table on the normal 14-day cadence and reboot. Note that Windows Server 2025 (KB5078740, build 26100.32522) diverges sharply in build minor from the 24H2 client (26100.8037) despite the shared 26100 base — confirmed on the live Microsoft support page, so do not treat the client KB as covering the server.

The soft call in this unit

The soft call is the tier itself: with zero exploitation this is defensibly a 30-day Track, and only Microsoft's 'exploitation more likely' forecast on six EoPs pulls it to a 14-day Prioritise. If that forecast does not match your telemetry, Track is defensible — the judgement is a forecast, and it is labelled as one.

2

Microsoft SQL Server (2016 and later)

Per-product servicing — see table
PRIORITISE
≤14 days

Why now. CVE-2026-21262 lets an authenticated database user reach sysadmin over the network through an improper access-control flaw — a full compromise of the instance's trust boundary. It is core infrastructure and the vector is network, but the impact is elevation of privilege, which is not a structural-gate impact class, so the tree files it Prioritise rather than Act. It was publicly disclosed at release (credited to Erland Sommarskog), which raises the chance a working technique circulates before your DBA change window — so close it inside two weeks rather than deferring to the next quarterly SQL maintenance.

ProductPackageCarries
Microsoft SQL Server 2016 / 2017 / 2019 / 2022 (GDR and CU trains)not establishedresolve via vendor advisory before deployment

Then. Apply the SQL Server GDR or CU update for your major version and build train (SQL patching is version- and train-specific; there is no single KB). Because exploitation requires an existing authenticated login, also review that application and service accounts hold least privilege in the interim.

The soft call in this unit

The judgement here is prioritise-versus-act. A network path to sysadmin reads like an act candidate, but it requires authentication and the impact class is EoP, so the structural gate keeps it at Prioritise. If the affected instance is internet-reachable or shares credentials broadly, treat the disclosure as reason to move at the fast end of the 14-day window.

The cut — why the top unit cannot slip

Confidence: moderate-high — analytic judgement, not vendor-attested

March 2026 is a genuine low-urgency cycle, and the correct output is a prioritise/track brief with no Act unit — not a manufactured emergency.

Basis. Six independent counters agree no CVE was exploited or publicly attacked at release, the live CISA KEV feed contains none of the March CVEs, and the only 9.8 is a cloud service fixed server-side with no customer package. With no evidence lane and nothing passing the structural impact gate, the decision tree produces no Act unit by construction.

What would lower this. A later KEV addition for any March CVE, or public proof-of-concept for the SQL Server EoP or an Office Preview-Pane RCE, would escalate the affected unit and change the top tier. The 'exploitation more likely' rating on the six EoPs is a forecast, not evidence, and would only matter if it converts to real exploitation.

What is not urgent — and why

1

Microsoft Office (Click-to-Run and MSI)

Per-product servicing — see table
TRACK
normal cycle

Why now. It is not now. CVE-2026-26110 and CVE-2026-26113 are Critical Office remote-code-execution flaws (8.4); CVE-2026-26110 is reachable through the Preview Pane, so no explicit file-open is required. But Office is neither exposed technology nor core infrastructure and neither flaw is exploited, so the tree files them Track. The Preview-Pane vector is the caveat and it is stated rather than buried.

ProductPackageCarries
Microsoft Office (Click-to-Run and MSI)not establishedresolve via vendor advisory before deployment

Then. Patch Office on the normal cycle (Click-to-Run auto-updates; MSI via WSUS/SCCM). Do not let the Critical label pull it ahead of the prioritise units above.

2

Microsoft .NET (9.0 / 10.0)

Per-product servicing — see table
TRACK
normal cycle

Why now. It is not now. CVE-2026-26127 is a .NET denial-of-service (7.5) via an out-of-bounds read, publicly disclosed but not exploited and rated Exploitation Unlikely by Rapid7. It is filed Track. It is worth updating hosted .NET services promptly only where availability is contractual, but nothing here forces a change window.

ProductPackageCarries
Microsoft .NET 9.0 / 10.0 runtimes and SDKsnot establishedresolve via vendor advisory before deployment

Then. Update affected .NET runtimes/SDKs on your normal application-patching cadence; rebuild and redeploy self-contained apps that bundle the runtime.

Method, sources, caveats

Sources

SourceAdmiraltyUsed for
https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilitiesA1KEV read 2026-07-17: none of the March 2026 Microsoft CVEs are present, consistent with zero exploitation at release
https://www.thezdi.com/blog/2026/3/10/the-march-2026-security-update-reviewB2Count (84), Critical (8); no CVEs under active attack; the 9.8 Devices Pricing Program RCE
https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-B2Count (83), Critical (8); SQL Server EoP 8.8 and .NET DoS 7.5 as the two disclosed CVEs; next-highest score 8.8
https://www.helpnetsecurity.com/2026/03/11/march-2026-patch-tuesday/B2The six 'exploitation more likely' EoPs (Kernel x2, SMB Server, Winlogon, Graphics, Accessibility) per Tenable's Satnam Narang
https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tueB2Count (79), Critical (3) in Windows-scoped view; the two publicly-disclosed CVEs; SQL Server credit to Erland Sommarskog
https://www.rapid7.com/blog/post/em-patch-tuesday-march-2026/B2Count (77); Exploitation Less Likely (SQL Server) / Unlikely (.NET); scoped 'no Critical' view
https://support.microsoft.com/en-us/topic/march-10-2026-kb5079473-os-builds-26A2Windows 11 25H2/24H2 package KB5079473 and builds of record