CRITICALVulnerability
Verified
Global

Microsoft Patches 97 Vulnerabilities Including Three Actively Exploited Zero-Days

·Source: Microsoft MSRC

Updated:

Executive Summary

March 2026 Patch Tuesday addresses 97 CVEs with three actively exploited zero-days in Windows kernel, NTLM, and Hyper-V.

Analysis

Microsoft March 2026 Patch Tuesday addresses 97 vulnerabilities across Windows, Office, Azure, and Exchange. Three zero-days are under active exploitation: CVE-2026-21399 (Windows kernel EoP), CVE-2026-21400 (NTLM hash leak), CVE-2026-21401 (Hyper-V guest escape). CISA added all three to KEV catalog with 21-day remediation deadline.

Timeline

Discovered
Mar 1, 2026
Exploitation Detected
Mar 1, 2026
Published
Mar 12, 2026
Patch Available
Mar 12, 2026

Indicators of Compromise (3)

CVE (3)
CVE-2026-21399
CVE-2026-21400
CVE-2026-21401
Source Attribution

Originally published by Microsoft MSRC on Mar 12, 2026. Verified by: Microsoft, CISA.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-105571 — A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is ...

A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early throu

CVE-2026-105571
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-105486 — A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the functio...

A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d9

CVE-2026-105486
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-105484 — A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230...

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.

CVE-2026-105484
NIST NVD