This is a prioritise month, not an act month — and that is the finding. Every counter agrees no March CVE was exploited in the wild or is in CISA KEV. There is no evidence-lane emergency and nothing reaches the structural act gate. The Windows cumulative ships on the normal 14-day cadence; treat the calm as real, not as something to manufacture urgency around.
The Windows cumulative still leads, for six 'exploitation more likely' elevation bugs. Tenable flags six EoP flaws Microsoft rates more likely to be exploited — two in the Windows Kernel (CVE-2026-24289, CVE-2026-26132), plus SMB Server (CVE-2026-24294), Winlogon (CVE-2026-25187), Graphics (CVE-2026-23668) and Accessibility (CVE-2026-24291). None is exploited today; the rating is a forecast, and it is why this cumulative is a 14-day prioritise rather than a 30-day track.
Two flaws were publicly disclosed but not exploited. CVE-2026-21262 is a SQL Server elevation-of-privilege bug (8.8) that hands an authenticated user sysadmin over the network, credited to Erland Sommarskog; CVE-2026-26127 is a .NET denial-of-service (7.5). Public disclosure raises the odds that a technique circulates, so both are tracked deliberately — but neither is under attack.
The month's only CVSS-9.8 needs no action from you. CVE-2026-21536 in the Microsoft Devices Pricing Program is an unauthenticated cloud RCE that Microsoft patched server-side — there is no package to deploy. This is exactly why the narrower counters (Rapid7, BleepingComputer) report 'no 9.8' and even 'no Critical': they scope out cloud-side fixes. Do not let a 9.8 headline pull an on-prem change window it does not require.
The Office criticals are Preview-Pane RCEs, and they are track, not act. CVE-2026-26110 and CVE-2026-26113 are Office remote-code-execution flaws scored 8.4, one reachable through the Preview Pane. Office is neither exposed technology nor core infrastructure and neither flaw is exploited, so they ship on the normal cycle — with the Preview-Pane vector noted as the one caveat.
Why now. Not urgently. No flaw in this cumulative is exploited or in KEV, so it does not qualify for the evidence lane, and every notable flaw is a local-vector elevation of privilege that fails the structural impact gate — so it is Prioritise, not Act. What keeps it ahead of a 30-day track is that six of the EoPs (two in the Kernel, plus SMB Server, Winlogon, Graphics and Accessibility) carry Microsoft's 'exploitation more likely' rating: these are the classic second stage of a local intrusion, so closing them inside two weeks shortens the window in which a foothold becomes SYSTEM.
| Product | Package | Carries |
|---|---|---|
| Windows 11 25H2 / 24H2 | KB5079473 | CVE-2026-24289, CVE-2026-24294, CVE-2026-25187 |
| Windows 11 23H2 | KB5078883 | CVE-2026-24289, CVE-2026-24294, CVE-2026-25187 |
| Windows 10 22H2 (ESU) | KB5078885 | CVE-2026-24289, CVE-2026-24294, CVE-2026-25187 |
| Windows Server 2025 | KB5078740 | CVE-2026-24289, CVE-2026-24294, CVE-2026-25187 |
| Windows Server 2022 | KB5078766 | CVE-2026-24289, CVE-2026-24294, CVE-2026-25187 |
| Windows Server 2019 | KB5078752 | CVE-2026-24289, CVE-2026-24294 |
| Windows Server 2016 | KB5078938 | CVE-2026-24289, CVE-2026-24294 |
Also inside: The Kernel pair is CVE-2026-24289 and CVE-2026-26132; the other 'more likely' EoPs are CVE-2026-23668 (Graphics Component) and CVE-2026-24291 (Accessibility Infrastructure). The same servicing stack also ships the publicly-disclosed .NET denial-of-service CVE-2026-26127 (7.5) on servers that run affected .NET runtimes.
Then. Deploy the per-product package for your build from the table on the normal 14-day cadence and reboot. Note that Windows Server 2025 (KB5078740, build 26100.32522) diverges sharply in build minor from the 24H2 client (26100.8037) despite the shared 26100 base — confirmed on the live Microsoft support page, so do not treat the client KB as covering the server.
The soft call is the tier itself: with zero exploitation this is defensibly a 30-day Track, and only Microsoft's 'exploitation more likely' forecast on six EoPs pulls it to a 14-day Prioritise. If that forecast does not match your telemetry, Track is defensible — the judgement is a forecast, and it is labelled as one.
Why now. CVE-2026-21262 lets an authenticated database user reach sysadmin over the network through an improper access-control flaw — a full compromise of the instance's trust boundary. It is core infrastructure and the vector is network, but the impact is elevation of privilege, which is not a structural-gate impact class, so the tree files it Prioritise rather than Act. It was publicly disclosed at release (credited to Erland Sommarskog), which raises the chance a working technique circulates before your DBA change window — so close it inside two weeks rather than deferring to the next quarterly SQL maintenance.
| Product | Package | Carries |
|---|---|---|
| Microsoft SQL Server 2016 / 2017 / 2019 / 2022 (GDR and CU trains) | not established | resolve via vendor advisory before deployment |
Then. Apply the SQL Server GDR or CU update for your major version and build train (SQL patching is version- and train-specific; there is no single KB). Because exploitation requires an existing authenticated login, also review that application and service accounts hold least privilege in the interim.
The judgement here is prioritise-versus-act. A network path to sysadmin reads like an act candidate, but it requires authentication and the impact class is EoP, so the structural gate keeps it at Prioritise. If the affected instance is internet-reachable or shares credentials broadly, treat the disclosure as reason to move at the fast end of the 14-day window.
March 2026 is a genuine low-urgency cycle, and the correct output is a prioritise/track brief with no Act unit — not a manufactured emergency.
Basis. Six independent counters agree no CVE was exploited or publicly attacked at release, the live CISA KEV feed contains none of the March CVEs, and the only 9.8 is a cloud service fixed server-side with no customer package. With no evidence lane and nothing passing the structural impact gate, the decision tree produces no Act unit by construction.
What would lower this. A later KEV addition for any March CVE, or public proof-of-concept for the SQL Server EoP or an Office Preview-Pane RCE, would escalate the affected unit and change the top tier. The 'exploitation more likely' rating on the six EoPs is a forecast, not evidence, and would only matter if it converts to real exploitation.
Why now. It is not now. CVE-2026-26110 and CVE-2026-26113 are Critical Office remote-code-execution flaws (8.4); CVE-2026-26110 is reachable through the Preview Pane, so no explicit file-open is required. But Office is neither exposed technology nor core infrastructure and neither flaw is exploited, so the tree files them Track. The Preview-Pane vector is the caveat and it is stated rather than buried.
| Product | Package | Carries |
|---|---|---|
| Microsoft Office (Click-to-Run and MSI) | not established | resolve via vendor advisory before deployment |
Then. Patch Office on the normal cycle (Click-to-Run auto-updates; MSI via WSUS/SCCM). Do not let the Critical label pull it ahead of the prioritise units above.
Why now. It is not now. CVE-2026-26127 is a .NET denial-of-service (7.5) via an out-of-bounds read, publicly disclosed but not exploited and rated Exploitation Unlikely by Rapid7. It is filed Track. It is worth updating hosted .NET services promptly only where availability is contractual, but nothing here forces a change window.
| Product | Package | Carries |
|---|---|---|
| Microsoft .NET 9.0 / 10.0 runtimes and SDKs | not established | resolve via vendor advisory before deployment |
Then. Update affected .NET runtimes/SDKs on your normal application-patching cadence; rebuild and redeploy self-contained apps that bundle the runtime.
| Source | Admiralty | Used for |
|---|---|---|
| https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities | A1 | KEV read 2026-07-17: none of the March 2026 Microsoft CVEs are present, consistent with zero exploitation at release |
| https://www.thezdi.com/blog/2026/3/10/the-march-2026-security-update-review | B2 | Count (84), Critical (8); no CVEs under active attack; the 9.8 Devices Pricing Program RCE |
| https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83- | B2 | Count (83), Critical (8); SQL Server EoP 8.8 and .NET DoS 7.5 as the two disclosed CVEs; next-highest score 8.8 |
| https://www.helpnetsecurity.com/2026/03/11/march-2026-patch-tuesday/ | B2 | The six 'exploitation more likely' EoPs (Kernel x2, SMB Server, Winlogon, Graphics, Accessibility) per Tenable's Satnam Narang |
| https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tue | B2 | Count (79), Critical (3) in Windows-scoped view; the two publicly-disclosed CVEs; SQL Server credit to Erland Sommarskog |
| https://www.rapid7.com/blog/post/em-patch-tuesday-march-2026/ | B2 | Count (77); Exploitation Less Likely (SQL Server) / Unlikely (.NET); scoped 'no Critical' view |
| https://support.microsoft.com/en-us/topic/march-10-2026-kb5079473-os-builds-26 | A2 | Windows 11 25H2/24H2 package KB5079473 and builds of record |