CVE-2004-0935, CVE-2019-17571, CVE-2024-13159, CVE-2024-13160, CVE-2024-13161, CVE-2024-29824, CVE-2026-0866, CVE-2026-1603, CVE-2026-21262, CVE-2026-23668, CVE-2026-23669, CVE-2026-23813, CVE-2026-24289, CVE-2026-24291, CVE-2026-24294, CVE-2026-24297, CVE-2026-25166, CVE-2026-25172, CVE-2026-25187, CVE-2026-26030, CVE-2026-26105, CVE-2026-26106, CVE-2026-26110, CVE-2026-26113, CVE-2026-26114, CVE-2026-26118, CVE-2026-26127, CVE-2026-26128, CVE-2026-26132, CVE-2026-26144, CVE-2026-26148, CVE-2026-27685, CVE-2026-3611
Get tomorrow's brief in your inbox
Today: Microsoft patches 79 flaws including Excel bug that weaponizes Copilot for zero-click data theft. CISA flags Ivanti EPM flaw as actively exploited with March 23 federal deadline. BlackSanta EDR killer targets HR departments with fake resumes. HPE warns of critical AOS-CX switch authentication bypass. New Zombie ZIP technique evades 50 of 51 antivirus engines.
CISA: Ivanti EPM Authentication Bypass (CVE-2026-1603) Actively Exploited
CISA added CVE-2026-1603 to its Known Exploited Vulnerabilities catalog on March 10, flagging active exploitation of this high-severity Ivanti Endpoint Manager authentication bypass. The flaw allows remote attackers without credentials to steal authentication data via cross-site scripting attacks requiring no user interaction. Ivanti patched the vulnerability one month ago in EPM 2024 SU5, but CISA has now ordered federal agencies to patch within three weeks by March 23. Shadowserver tracks over 700 internet-facing EPM instances, most in North America. Ivanti reports no confirmed exploitation prior to public disclosure but threat actors routinely target EPM vulnerabilities. CISA also flagged three other EPM flaws last year (CVE-2024-13159, CVE-2024-13160, CVE-2024-13161) that were exploited in the wild, and another actively exploited flaw (CVE-2024-29824) in October 2024.
Microsoft Excel Zero-Click Copilot Data Exfiltration (CVE-2026-26144)
Microsoft patched CVE-2026-26144, a critical information disclosure flaw in Excel that weaponizes Copilot Agent mode to exfiltrate data via unintended network egress in a zero-click attack. The cross-site scripting vulnerability requires network access but no user interaction or privilege escalation. An attacker could craft a malicious Excel file that causes Copilot Agent to silently extract confidential information such as financial data, intellectual property, or operational records without triggering alerts. Zero Day Initiative's Dustin Childs calls this "an attack scenario we're likely to see more often." Microsoft assesses exploitation as unlikely, but the attack vector is novel and combines AI tooling with traditional XSS techniques.
HPE Aruba AOS-CX Critical Authentication Bypass (CVE-2026-23813)
HPE patched a critical authentication bypass (CVE-2026-23813, CVSS 9.8) in the web management interface of Aruba Networking AOS-CX switches that allows unauthenticated remote attackers to reset admin passwords. The vulnerability affects CX-series campus and data center switches running AOS-CX. HPE reports no public exploit code or evidence of active exploitation but warns that successful compromise gives attackers full control of network devices and the ability to disrupt communications or pivot laterally. Exploitation has low complexity and requires no privileges or user interaction.
Microsoft March 2026 Patch Tuesday: 79 Vulnerabilities, No Active Exploits
Microsoft released its March 2026 Patch Tuesday addressing 79 vulnerabilities across its enterprise portfolio, marking the first monthly update without an actively exploited zero-day in six months. The update includes 8 Critical and 71 Important severity flaws. Two vulnerabilities were publicly disclosed but not exploited: CVE-2026-26127 (denial-of-service in .NET via out-of-bounds read) and CVE-2026-21262 (SQL Server privilege escalation via improper access control allowing authenticated attackers to gain sysadmin privileges). More than half of the flaws trigger privilege escalation, with six rated as more likely to be exploited: CVE-2026-23668, CVE-2026-24289, CVE-2026-24291, CVE-2026-24294, CVE-2026-25187, and CVE-2026-26132. Notable fixes include CVE-2026-25187, a Winlogon privilege escalation via improper link resolution allowing locally authenticated low-privilege attackers to obtain SYSTEM privileges, and CVE-2026-26118, a server-side request forgery bug in Azure Model Context Protocol server allowing authorized attackers to capture managed identity tokens.
Microsoft Office Preview Pane RCE Vulnerabilities (CVE-2026-26110, CVE-2026-26113)
Two critical-severity remote code execution flaws in Microsoft Office (CVE-2026-26110 and CVE-2026-26113, both CVSS 8.4) can be triggered via the Preview Pane, meaning attackers can execute arbitrary code without users fully opening malicious files. CVE-2026-26110 stems from type confusion allowing remote code execution when Office accesses resources using incompatible data types. CVE-2026-26113 is caused by untrusted pointer dereference allowing remote attackers to manipulate memory pointers. Both vulnerabilities require no user interaction beyond previewing a file, making them particularly dangerous in environments where documents are shared via email, file shares, and collaboration platforms. Zero Day Initiative notes these Preview Pane RCE flaws have become increasingly common over the last year and warns "it's just a matter of time until they start appearing in active exploits."
Windows Autopatch Enables Hotpatching by Default in May 2026
Microsoft will enable hotpatch security updates by default in Windows Autopatch starting with the May 2026 update. Hotpatching installs security updates without reboots, with changes taking effect immediately after one baseline update with restart. Every quarterly baseline update still requires a restart. The change applies to devices running Windows 11 24H2 or later with the April 2026 security update installed. Opt-out controls will be available from April 1 at the tenant or device group policy level. Microsoft argues hotpatch updates are "the quickest way to get secure," but the compressed two-month timeline and addition of another variable that could produce unexpected consequences concerns administrators who prize tight control over patching environments.
Azure AD SSH Login Extension Privilege Escalation (CVE-2026-26148)
Microsoft patched CVE-2026-26148, an elevation of privilege vulnerability in the Azure AD SSH Login extension for Linux caused by external initialization of trusted variables or data stores. The flaw allows unauthorized attackers to elevate privileges locally on systems using Azure Entra ID SSH authentication.
Windows Kerberos Security Feature Bypass (CVE-2026-24297)
Microsoft addressed CVE-2026-24297, a race condition in Windows Kerberos that allows unauthorized attackers to bypass security features over a network. The vulnerability stems from concurrent execution using shared resources with improper synchronization.
SharePoint Server Spoofing Vulnerability (CVE-2026-26105)
Microsoft patched CVE-2026-26105, a cross-site scripting flaw in SharePoint Server that allows unauthorized attackers to perform spoofing over a network via improper neutralization of input during web page generation.
Windows Print Spooler RCE (CVE-2026-23669)
Microsoft fixed CVE-2026-23669, a use-after-free vulnerability in Windows Print Spooler components that allows authorized attackers to execute code over a network. This continues the long history of Print Spooler vulnerabilities exploited in ransomware campaigns.
Windows System Image Manager ADK RCE (CVE-2026-25166)
Microsoft addressed CVE-2026-25166, a deserialization of untrusted data vulnerability in Windows System Image Manager that allows authorized attackers to execute code locally.
Windows RRAS RCE (CVE-2026-25172)
Microsoft patched CVE-2026-25172, an integer overflow vulnerability in Windows Routing and Remote Access Service that allows unauthorized attackers to execute code over a network.
BlackSanta EDR Killer Targets HR Departments with Fake Resumes
A Russian-speaking threat actor has targeted corporate HR teams for over a year with malware that delivers BlackSanta, a new EDR killer designed to disable endpoint security before deploying final payloads. Aryaka researchers report the campaign uses fake job applications hosted on cloud storage services such as Dropbox, distributing ISO image files that appear to be resumes. The ISO contains a Windows shortcut disguised as a PDF that launches PowerShell to execute hidden code extracted via steganography from an image file. The malware performs extensive environment checks to detect sandboxes, virtual machines, and debugging tools, then downloads additional payloads via process hollowing. BlackSanta adds Microsoft Defender exclusions for .dls and .sys files, modifies Registry values to reduce telemetry, suppresses Windows notifications, and terminates security processes at the kernel level using Bring Your Own Vulnerable Driver techniques. The campaign uses legitimate but buggy drivers including RogueKiller Antirootkit v3.1.0 and IObitUnlocker.sys v1.2.0.1 to gain elevated privileges and bypass file and process locks. Researchers could not retrieve the final payload as the C2 server was unavailable during analysis but identified multiple IP addresses indicating the operation has been active for the past year.
3 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| leaknet | CIS | Unknown | Unknown |
| eraleign (apt73) | banak.com | Retail (Furniture/Home Decor) | Spain |
| eraleign (apt73) | bankasia-bd.com | Banking | Bangladesh |
Sources: RansomLook | RansomLook
Zombie ZIP Technique Evades 50 of 51 Antivirus Engines
Bombadil Systems researcher Chris Aziz disclosed a new technique dubbed "Zombie ZIP" that conceals malware payloads in specially crafted compressed files that evade detection from 50 of 51 antivirus engines on VirusTotal. The technique manipulates ZIP headers to trick parsing engines into treating compressed data as uncompressed by setting the Method field to 0 (STORED) while the data remains DEFLATE compressed. Security tools trust the header and scan the file as raw uncompressed bytes, seeing only compressed noise that matches no malware signatures. Standard extraction utilities like WinRAR and 7-Zip fail with errors or produce corrupted data, but a purpose-built loader that ignores the declared method and decompresses as DEFLATE recovers the payload perfectly. The CRC value is set to the uncompressed payload's checksum to cause popular tools to generate extraction errors. CERT/CC published a bulletin assigning CVE-2026-0866 and noting similarity to CVE-2004-0935, an ESET antivirus vulnerability from two decades ago. CERT/CC recommends security vendors validate compression method fields against actual data and implement aggressive archive inspection modes.
SAP Critical Code Injection and Deserialization Flaws
SAP released security updates for two critical vulnerabilities: CVE-2019-17571 (CVSS 9.8), a code injection flaw in SAP Quotation Management Insurance application (FS-QUO) using outdated Apache Log4j 1.2.17, and CVE-2026-27685 (CVSS 9.1), an insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration. CVE-2019-17571 allows unprivileged remote attackers to execute arbitrary code on the server, causing high impact on confidentiality, integrity, and availability. CVE-2026-27685 stems from missing validation during deserialization of uploaded content, allowing attackers to upload malicious content. Onapsis notes only the requirement for high privileges prevents the flaw from receiving a CVSS score of 10.
Adobe Patches 80 Vulnerabilities Across Product Portfolio
Adobe released March 2026 security updates addressing 80 vulnerabilities across Commerce, Magento Open Source, Illustrator, Substance 3D Painter, Acrobat Reader, Premiere Pro, and other products. Four critical flaws in Adobe Commerce and Magento Open Source could result in privilege escalation and security feature bypass. Five critical vulnerabilities in Adobe Illustrator could enable arbitrary code execution. None of the flaws are tagged as exploited.
ICS Vendors Release March Patch Tuesday Updates
Siemens, Schneider Electric, Mitsubishi Electric, and Moxa published ICS Patch Tuesday advisories addressing vulnerabilities in operational technology environments. CISA also released advisories for Lantronix EDS3000PS and EDS5000 serial device servers (8 vulnerabilities including OS command injection allowing root-level code execution), Apeman ID71 cameras (3 vulnerabilities including missing authentication and credential exposure), and Honeywell IQ4x BMS controllers (CVE-2026-3611, missing authentication allowing remote attackers to lock out legitimate operators and control building management systems).
Microsoft Semantic Kernel Python SDK RCE (CVE-2026-26030)
Microsoft addressed CVE-2026-26030, a remote code execution vulnerability in the Microsoft Semantic Kernel Python SDK InMemoryVectorStore filter functionality. GitHub created the CVE on Microsoft's behalf. Updates have been incorporated into the Semantic Kernel repository.
Iran-Linked Threat Actors Use Cybercrime Malware for Espionage and Obfuscation
Check Point Research reports Iranian Ministry of Intelligence and Security (MOIS)-linked threat actors increasingly use cybercrime malware and ransomware infrastructure in espionage operations, not just as cover for destructive activity. MuddyWater (Seedworm, Static Kitten) and Void Manticore (Storm-842, Handala Hack) show repeated overlaps with criminal organizations and their tools. Void Manticore, a hacktivist crew that uses wipers, data leaks, and disinformation for Iranian government objectives targeting Israel, recently added the commercial infostealer Rhadamanthys (sold on cybercrime forums) to its arsenal. International law enforcement disrupted Rhadamanthys infrastructure in November 2025, seizing 1,025 servers, but the malware operators recovered. Handala Hack typically pairs Rhadamanthys with custom data wipers in phishing emails sent to Israeli targets, often impersonating F5 updates or the Israeli National Cyber Directorate. MuddyWater has conducted espionage since 2018 and recently burrowed into critical US networks following US and Israeli airstrikes against Iran using a new backdoor called DinDoor, a variant of the Tsundere botnet. MuddyWater also uses FakeSet downloader to deliver CastleLoader, a malware-as-a-service offering sold to multiple affiliates. Check Point notes the use of criminal tools creates significant confusion leading to misattribution and flawed pivoting, demonstrating that criminal software can be effective for obfuscation.
Proofpoint: Iran Conflict Drives Espionage Activity Targeting Middle East
Proofpoint observed heightened espionage activity targeting Middle East government organizations since the US and Israeli Operation Epic Fury strikes against Iran began on February 28, 2026. The Iran-aligned threat actor TA453 (Charming Kitten, Mint Sandstorm, APT42) conducted credential phishing on March 8 against a US think tank target, continuing intelligence collection despite Iranian government internet shutdowns. Proofpoint tracked campaigns from suspected China, Belarus, Pakistan, and Hamas-aligned actors heavily relying on conflict-themed lure content and using compromised government email accounts to send phishing. The suspected China-aligned actor UNK_InnerAmbush conducted campaigns starting March 1 targeting Middle Eastern government and diplomatic organizations with phishing emails linking to password-protected archives containing malicious LNK files disguised as JPG images. The archives load a Cobalt Strike payload using DLL sideloading and communicate with customized C2 infrastructure. Proofpoint assesses this activity reflects threat actors opportunistically using the war as lure content for routine operations and those with increased focus on intelligence collection targeting Middle Eastern government and diplomatic entities.
Microsoft March 2026 Patch Tuesday Highlights
Beyond the critical and publicly disclosed vulnerabilities listed above, Microsoft's March update addresses 46 elevation of privilege flaws, 18 remote code execution bugs, 10 information disclosure vulnerabilities, 4 spoofing issues, 4 denial-of-service flaws, and 2 security feature bypass vulnerabilities. Key fixes include CVE-2026-26106 and CVE-2026-26114, remote code execution flaws in SharePoint Server caused by improper input validation and deserialization of untrusted data respectively, allowing authenticated attackers with Site Member permissions to execute code remotely. CVE-2026-26128 is an elevation of privilege vulnerability in Windows SMB Server caused by improper authentication, allowing authorized attackers to elevate privileges over a network. Windows 11 KB5079473 and KB5078883 cumulative updates add Emoji 16.0 support, Windows Backup for Organizations first sign-in restore for Microsoft Entra hybrid joined devices, Quick Machine Recovery enabled by default for non-domain-joined Windows Professional devices, built-in network speed test in taskbar, camera pan/tilt controls, and native System Monitor (Sysmon) functionality for threat detection. Windows 10 KB5078885 extended security update fixes the Secure Launch hibernation restart issue and continues Secure Boot certificate rollout to replace 2011 certificates expiring in June 2026.
Dozens of Vendors Release March 2026 Security Updates
In addition to Microsoft, SAP, Adobe, and HPE, security updates were released by ABB, Amazon Web Services, AMD, Arm, Atlassian, Bosch, Broadcom (VMware), Canon, Cisco, Commvault, Dassault Systèmes, Dell, Devolutions, Drupal, Elastic, F5, Fortinet, Fortra, Foxit Software, GitLab, Google (Android, Pixel, Chrome, Cloud, Pixel Watch, Wear OS), Grafana, Hitachi Energy, Honeywell, HP, IBM, Intel, Ivanti, Jenkins, Lenovo, Linux distributions (AlmaLinux, Alpine, Amazon Linux, Arch, Debian, Gentoo, Oracle, Mageia, Red Hat, Rocky, SUSE, Ubuntu), MediaTek, Mitsubishi Electric, Moxa, Mozilla (Firefox, Firefox ESR, Thunderbird), n8n, NVIDIA, Palo Alto Networks, QNAP, Qualcomm, Ricoh, Samsung, Schneider Electric, ServiceNow, Siemens, SolarWinds, Splunk, Synology, TP-Link, Trend Micro, WatchGuard, Western Digital, Zoom, and Zyxel. Google's Android March security bulletin fixed an actively exploited zero-day in a Qualcomm display component. Fortinet released updates for FortiOS, FortiPAM, and FortiProxy.
March 2026 Patch Tuesday delivers a welcome reprieve from the zero-day onslaught that defined the first two months of the year. Microsoft's six-month streak of actively exploited vulnerabilities ends, but the threat landscape remains aggressive. The Excel Copilot data exfiltration bug signals a new attack category where AI features become vectors for zero-click information disclosure. Preview Pane RCE vulnerabilities continue their rise, with researchers warning active exploitation is inevitable. The BlackSanta EDR killer targeting HR departments underscores that recruitment pipelines are now treated as high-value attack vectors by sophisticated threat actors using kernel-level defense evasion techniques. The Zombie ZIP evasion method bypassing 50 of 51 antivirus engines demonstrates that adversaries continue to find creative ways to defeat signature-based detection. Organizations should prioritize March patches, treat HR file intake with the same rigor as finance workflows, and prepare for the May 2026 Windows Autopatch hotpatching changes that will reshape patching workflows for Windows 11 environments.