Patch Tuesday 2026
The latest Patch Tuesday 2026 coverage — news, analysis, and updates from the WindowsNews.AI desk.
Excel CVE-2026-26144 XSS Vulnerability Enables Copilot Data Exfiltration in Zero-Click Attack
Microsoft's March 2026 Patch Tuesday addressed a critical Excel vulnerability that creates a dangerous new attack vector for AI-powered data theft. CVE-2026-26144, a cross-site scripting flaw in...
Microsoft Patches ATBroker Information Disclosure Vulnerability CVE-2026-25186 in Windows Accessibility Infrastructure
Microsoft has addressed a newly cataloged information disclosure vulnerability in the Windows Accessibility Infrastructure, tracked as CVE-2026-25186, affecting the ATBroker.exe helper process. This...
Microsoft Patches Windows Graphics Component DoS Vulnerability CVE-2026-25168 in March 2026 Update
Microsoft's March 2026 security update addresses a critical denial-of-service vulnerability in the Windows Graphics Component, tracked as CVE-2026-25168. This local null-pointer dereference flaw...
CVE-2026-25165: Critical Windows Performance Counters Vulnerability Allows Local Privilege Escalation
Microsoft has disclosed CVE-2026-25165, a critical elevation-of-privilege vulnerability in the Windows Performance Counters subsystem. This null-pointer dereference flaw allows attackers with local...
Microsoft Patches Critical Windows Device Association Service Race Condition in March 2026 Patch Tuesday
Microsoft's March 10, 2026 Patch Tuesday security update addresses a critical vulnerability in the Windows Device Association Service that could allow local privilege escalation. Tracked as...
Microsoft Patches Critical SMB Server EoP Vulnerability CVE-2026-24294 in March 2026 Update
Microsoft has released a security update addressing CVE-2026-24294, an elevation-of-privilege vulnerability in the Windows Server Message Block (SMB) Server component. The company classifies this...
Microsoft Patches Critical AFD.sys Privilege Escalation Vulnerability CVE-2026-24293 in March 2026 Emergency Update
Microsoft released emergency security fixes on March 10, 2026, addressing CVE-2026-24293, a high-impact elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock...
Microsoft Patches Critical Windows Kernel Elevation Vulnerability CVE-2026-24289 in March 2026 Update
Microsoft's March 2026 Patch Tuesday addressed a significant Windows kernel elevation-of-privilege vulnerability tracked as CVE-2026-24289. The company rated this security flaw as Important,...
Windows 11 KB5078883: Microsoft's Phased Secure Boot Certificate Refresh Explained
Microsoft's March 10, 2026 cumulative update for Windows 11 (KB5078883, OS Build 22631.6783) delivers more than routine security patches. The update initiates a phased refresh of Secure Boot...
CVE-2026-23672: Microsoft Patches Windows UDFS Vulnerability Granting Full System Access
On March 10, 2026, Microsoft fixed a high‑severity elevation‑of‑privilege flaw in the Windows Universal Disk Format (UDF) file system driver. Labeled CVE‑2026‑23672, the vulnerability...
KB5079473 adds Sysmon and Emoji 16 as Windows 11 fixes 72 CVEs.
Microsoft's March 2026 Patch Tuesday delivers KB5079473, a cumulative update for Windows 11 that introduces two significant additions: System Monitor (Sysmon) as an in-box component and support for...
Microsoft Confirms No Exchange Security Updates for March 2024 Patch Tuesday
Microsoft's Exchange engineering team delivered a clear message to administrators this month: no security updates are coming for on-premises Exchange Server during March 2024's Patch Tuesday. This...