Patch Tuesday - March 2026

2026-03-11T07:23:46Z6e709450c578866a6574f1b819a05261a1ca212a15d755e856aef2458b73fa44
AI-connectorsCVE-2026-21262DASTattack-surface-managementclickfixcloudflare-captchacredential-theftelevation-of-privilegeexploit-modulesin-memory-malwaremalicious-websitesmetasploitmicrosoftpatch-tuesdaypublic-disclosurepurple-teamingsql-serverstealervulnerability-managementwordpress-compromisezero-day

What happened

This Rapid7 collection highlights March 2026 security news and guidance: Microsoft’s March Patch Tuesday (77 CVEs) includes a publically disclosed SQL Server elevation-of-privilege (CVE-2026-21262) that can allow an authenticated attacker to escalate to sysadmin over the network (CVSSv3 8.8). Rapid7 Labs documents a large WordPress compromise campaign (active since Dec 2025) that injects a ClickFix fake Cloudflare CAPTCHA to deliver an in-memory stealer that exfiltrates credentials and wallets from visitors across >250 legitimate sites in at least 12 countries. Other items cover purple teaming

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
6e709450c578866a6574f1b819a05261a1ca212a15d755e856aef2458b73fa44
Enrichment time
2026-03-11T07:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.