Microsoft Patch Tuesday security updates for March 2026 fixed 84 bugs
2026-03-11T08:51:49Z•bb184de517ebb791d9fad08e283cbcd3a21febe45f2b4f3c9da2a6d1b92bbe8f
2fa-phishingapt28aurainspectorbeardshellcisaconfiguration-theftcovenantdata-breachericssonfbi-alertfortigateivantiknown-exploited-vulnerabilitiesmicrosoftomnissapatch-tuesdayphishing-as-a-servicesalesforcesentinelonesignalsolarwindsthird-party-breachtycoonvulnerabilitieswhatsapp-targeting-russia-linked-actors','cognizant','trizetto'
What happened
Multiple significant cyber events reported: Microsoft released its March 2026 Patch Tuesday addressing 84 vulnerabilities across Windows, Office, Edge, Azure, SQL Server, Hyper-V and ReFS. Attackers are actively exploiting FortiGate devices (via vulnerabilities or weak credentials) to steal device configurations and service account credentials. ESET attributes long-term espionage against Ukrainian forces to APT28 using BEARDSHELL and COVENANT. Threat actors are mass-scanning Salesforce Experience Cloud sites with a modified AuraInspector to exploit misconfigurations and harvest data. CISA has/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- bb184de517ebb791d9fad08e283cbcd3a21febe45f2b4f3c9da2a6d1b92bbe8f
- Enrichment time
- 2026-03-11T08:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.