Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-03-10
Microsoft patched 83 CVEs in March including two zero-day vulnerabilities that were publicly disclosed, including CVE-2026-21262 and CVE-2026-26127.
https://www.infosecurity-magazine.com/news/microsoft-fixes-two-publicly/
https://www.helpnetsecurity.com/2026/03/11/march-2026-patch-tuesday/
https://www.darkreading.com/application-security/microsoft-patches-83-cves-march-update
https://thehackernews.com/2026/03/microsoft-patches-84-flaws-in-march.html
https://hackread.com/microsoft-march-patch-tuesday-two-0-days-flaws/
https://www.theregister.com/2026/03/10/zeroclick_microsoft_info_disclosure_bug/
https://www.securityweek.com/microsoft-patches-83-vulnerabilities/