ΑρχικήUpdatesΚυκλοφόρησε το Microsoft Patch Tuesday Μαρτίου 2026

Κυκλοφόρησε το Microsoft Patch Tuesday Μαρτίου 2026

Το Patch Tuesday Μαρτίου 2026 από τη Microsoft φέρνει ένα εκτεταμένο πακέτο ενημερώσεων ασφαλείας που στοχεύει στη διόρθωση 79 διαφορετικών ευπαθειών στο οικοσύστημα της εταιρείας. Ανάμεσα στα προβλήματα, που αντιμετωπίζονται, περιλαμβάνονται και δύο zero-day ευπάθειες που είχαν ήδη δημοσιοποιηθεί πριν διατεθεί επίσημο patch, γεγονός που αυξάνει το ενδιαφέρον της κοινότητας κυβερνοασφάλειας.

Microsoft Patch Tuesday Μαρτίου

Κρίσιμα κενά ασφαλείας και κατηγορίες ευπαθειών

Συνολικά, οι ενημερώσεις αυτής της περιόδου περιλαμβάνουν τρεις κρίσιμες ευπάθειες, από τις οποίες οι δύο σχετίζονται με απομακρυσμένη εκτέλεση κώδικα, ενώ η τρίτη αφορά αποκάλυψη ευαίσθητων πληροφοριών. Τα σφάλματα κατανέμονται σε πολλές κατηγορίες, δείχνοντας πόσο ευρύ είναι το πεδίο των πιθανών επιθέσεων.

Συγκεκριμένα καταγράφονται 46 ευπάθειες ανύψωσης προνομίων, 18 σφάλματα απομακρυσμένης εκτέλεσης κώδικα, 10 ευπάθειες αποκάλυψης πληροφοριών, 4 ευπάθειες που επιτρέπουν Denial of Service επιθέσεις, 4 ευπάθειες πλαστογράφησης και 2 παρακάμψεις μηχανισμών ασφαλείας.

Patch Tuesday Μαρτίου 2026: Δύο zero-days στο επίκεντρο

Ιδιαίτερη προσοχή συγκεντρώνουν οι δύο zero-day ευπάθειες που διορθώθηκαν αυτή τη φορά. Αν και καμία δεν έχει επιβεβαιωθεί ότι αξιοποιείται ενεργά σε πραγματικές επιθέσεις, η δημόσια αποκάλυψή τους πριν από τη διάθεση διορθώσεων αυξάνει τον κίνδυνο πιθανής εκμετάλλευσης.

Δείτε επίσης: Microsoft Patch Tuesday Φεβρουαρίου 2026: Διορθώσεις για 58 ευπάθειες

Η πρώτη, με κωδικό CVE-2026-21262, αφορά τον SQL Server και επιτρέπει ανύψωση δικαιωμάτων σε επίπεδο δικτύου. Σύμφωνα με την εταιρεία, ένας ήδη εξουσιοδοτημένος χρήστης θα μπορούσε να εκμεταλλευτεί ανεπαρκείς ελέγχους πρόσβασης και να αποκτήσει προνόμια SQLAdmin, αποκτώντας μεγαλύτερο έλεγχο στο σύστημα.

Η δεύτερη ευπάθεια, CVE-2026-26127, εντοπίζεται στο .NET και σχετίζεται με denial of service επιθέσεις. Μέσω Out-of-bounds read στο .NET , ένας μη εξουσιοδοτημένος επιτιθέμενος θα μπορούσε να προκαλέσει διακοπή λειτουργίας υπηρεσιών μέσα σε εταιρικά δίκτυα.

Ευπάθειες στο Office και κίνδυνοι μέσω preview pane

Οι ενημερώσεις περιλαμβάνουν επίσης δύο ευπάθειες απομακρυσμένης εκτέλεσης κώδικα στο Microsoft Office (CVE-2026-26110 και CVE-2026-26113). Τα συγκεκριμένα σφάλματα μπορούν να ενεργοποιηθούν ακόμη και μέσω του preview pane, κάτι που σημαίνει ότι ένας χρήστης μπορεί να εκτεθεί σε κίνδυνο απλώς προβάλλοντας ένα κακόβουλο αρχείο.

Ιδιαίτερο ενδιαφέρον παρουσιάζει και η ευπάθεια CVE-2026-26144 στο Microsoft Excel, η οποία θα μπορούσε να οδηγήσει σε διαρροή δεδομένων μέσω του Copilot. Σε περίπτωση επιτυχούς εκμετάλλευσης, ένας επιτιθέμενος θα μπορούσε να προκαλέσει ακούσια αποστολή πληροφοριών μέσω δικτύου, εκμεταλλευόμενος τον τρόπο με τον οποίο λειτουργεί ο Copilot Agent.

Κυκλοφόρησε το Microsoft Patch Tuesday Μαρτίου 2026

Τι σημαίνουν οι ενημερώσεις για επιχειρήσεις και χρήστες

Η μηνιαία διαδικασία ενημερώσεων παραμένει βασικός μηχανισμός προστασίας για οργανισμούς και ιδιώτες χρήστες. Οι ειδικοί ασφαλείας τονίζουν ότι η άμεση εγκατάσταση των patches μειώνει σημαντικά τις ευκαιρίες για κυβερνοεπιθέσεις.

Δείτε επίσης: Microsoft Patch Tuesday Ιανουαρίου 2026: Διόρθωση 114 ευπαθειών

Παράλληλα, το συγκεκριμένο Patch Tuesday υπενθυμίζει ότι ακόμη και ευρέως χρησιμοποιούμενες πλατφόρμες μπορούν να κρύβουν αδυναμίες που ανακαλύπτονται μήνες ή και χρόνια μετά την κυκλοφορία τους. Για τον λόγο αυτό, η συνεχής ενημέρωση συστημάτων και εφαρμογών θεωρείται κρίσιμη πρακτική ψηφιακής υγιεινής.

Εκτός λίστας ορισμένες πρόσφατες διορθώσεις

Αξίζει να σημειωθεί ότι ο συνολικός αριθμός των 79 ευπαθειών αφορά μόνο τις διορθώσεις που δημοσιεύθηκαν με το Patch Tuesday. Ορισμένα πρόσθετα προβλήματα ασφαλείας σε υπηρεσίες και προϊόντα της Microsoft είχαν ήδη αντιμετωπιστεί νωρίτερα μέσα στον μήνα.

Μεταξύ αυτών περιλαμβάνονται σφάλματα που επηρέαζαν τον Edge, το Azure, το Mariner και ορισμένες εσωτερικές υπηρεσίες πληρωμών και τιμολόγησης συσκευών. Αν και οι διορθώσεις αυτές δεν εντάχθηκαν στο πακέτο της ημέρας, παραμένουν σημαντικές για τη συνολική ασφάλεια του οικοσυστήματος.

Η σημασία του Patch Tuesday στο σύγχρονο τοπίο κυβερνοασφάλειας

Η καθιερωμένη Patch Tuesday έχει εξελιχθεί τα τελευταία χρόνια σε έναν από τους πιο σημαντικούς θεσμούς στον χώρο της κυβερνοασφάλειας. Κάθε μήνα συγκεντρώνει το ενδιαφέρον διαχειριστών συστημάτων, ερευνητών και εταιρειών που παρακολουθούν στενά τις νέες διορθώσεις.

Δείτε επίσης: Microsoft Patch Tuesday Μαρτίου 2025: Διορθώνει 57 ευπάθειες

Η γρήγορη ανάλυση των ευπαθειών επιτρέπει στις ομάδες IT να αξιολογήσουν τον βαθμό κινδύνου και να δώσουν προτεραιότητα στις πιο κρίσιμες ενημερώσεις. Σε περιβάλλοντα επιχειρήσεων, η διαδικασία αυτή συχνά συνοδεύεται από δοκιμές συμβατότητας πριν από τη μαζική εγκατάσταση.

Κυκλοφόρησε το Microsoft Patch Tuesday Μαρτίου 2026

Συστάσεις προς χρήστες και διαχειριστές

Οι ειδικοί προτείνουν στους χρήστες να ενεργοποιούν τις αυτόματες ενημερώσεις και να εγκαθιστούν άμεσα τα διαθέσιμα patches. Ιδιαίτερα σε περιπτώσεις που αφορούν zero-day ευπάθειες ή σφάλματα απομακρυσμένης εκτέλεσης κώδικα, η καθυστέρηση μπορεί να δημιουργήσει σοβαρά κενά άμυνας. Παράλληλα, οι οργανισμοί καλούνται να διατηρούν στρατηγικές δημιουργίας αντιγράφων ασφαλείας, εργαλεία ανίχνευσης απειλών και συνεχή παρακολούθηση δικτύου, ώστε να μειώνουν τον κίνδυνο εκμετάλλευσης νέων αδυναμιών. Η τακτική ενημέρωση παραμένει ένα από τα απλούστερα αλλά αποτελεσματικότερα μέτρα προστασίας για όλους.

Microsoft Patch Tuesday Μαρτίου: Όλες οι ευπάθειες που διορθώθηκαν

TagCVE IDCVE TitleSeverity
.NETCVE-2026-26131.NET Elevation of Privilege VulnerabilityImportant
.NETCVE-2026-26127.NET Denial of Service VulnerabilityImportant
Active Directory Domain ServicesCVE-2026-25177Active Directory Domain Services Elevation of Privilege VulnerabilityImportant
ASP.NET CoreCVE-2026-26130ASP.NET Core Denial of Service VulnerabilityImportant
Azure ArcCVE-2026-26141Hybrid Worker Extension (Arc-enabled Windows VMs) Elevation of Privilege VulnerabilityImportant
Azure Compute GalleryCVE-2026-23651Microsoft ACI Confidential Containers Elevation of Privilege VulnerabilityCritical
Azure Compute GalleryCVE-2026-26124Microsoft ACI Confidential Containers Elevation of Privilege VulnerabilityCritical
Azure Compute GalleryCVE-2026-26122Microsoft ACI Confidential Containers Information Disclosure VulnerabilityCritical
Azure Entra IDCVE-2026-26148Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege VulnerabilityImportant
Azure IoT ExplorerCVE-2026-26121Azure IOT Explorer Spoofing VulnerabilityImportant
Azure IoT ExplorerCVE-2026-23662Azure IoT Explorer Information Disclosure VulnerabilityImportant
Azure IoT ExplorerCVE-2026-23661Azure IoT Explorer Information Disclosure VulnerabilityImportant
Azure IoT ExplorerCVE-2026-23664Azure IoT Explorer Information Disclosure VulnerabilityImportant
Azure Linux Virtual MachinesCVE-2026-23665Linux Azure Diagnostic extension (LAD) Elevation of Privilege VulnerabilityImportant
Azure MCP ServerCVE-2026-26118Azure MCP Server Tools Elevation of Privilege VulnerabilityImportant
Azure Portal Windows Admin CenterCVE-2026-23660Windows Admin Center in Azure Portal Elevation of Privilege VulnerabilityImportant
Azure Windows Virtual Machine AgentCVE-2026-26117Arc Enabled Servers – Azure Connected Machine Agent Elevation of Privilege VulnerabilityImportant
Broadcast DVRCVE-2026-23667Broadcast DVR Elevation of Privilege VulnerabilityImportant
Connected Devices Platform Service (Cdpsvc)CVE-2026-24292Windows Connected Devices Platform Service Elevation of Privilege VulnerabilityImportant
GitHub Repo: zero-shot-scfoundationCVE-2026-23654GitHub: Zero Shot SCFoundation Remote Code Execution VulnerabilityImportant
MarinerCVE-2026-23235f2fs: fix out-of-bounds access in sysfs attribute read/writeImportant
MarinerCVE-2026-23234f2fs: fix to avoid UAF in f2fs_write_end_io()Important
MarinerCVE-2026-3713pnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflowModerate
MarinerCVE-2026-23237platform/x86: classmate-laptop: Add missing NULL pointer checksModerate
MarinerCVE-2026-26017CoreDNS ACL BypassImportant
MarinerCVE-2026-26018CoreDNS Loop Detection Denial of Service VulnerabilityImportant
MarinerCVE-2026-2297SourcelessFileLoader does not use io.open_code()Moderate
MarinerCVE-2026-0038In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Important
MarinerCVE-2026-27601Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attackImportant
MarinerCVE-2026-23236fbdev: smscufx: properly copy ioctl memory to kernelspaceModerate
MarinerCVE-2026-23865An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.Moderate
MarinerCVE-2025-71238scsi: qla2xxx: Fix bsg_done() causing double freeModerate
MarinerCVE-2026-3338PKCS7_verify Signature Validation Bypass in AWS-LCImportant
MarinerCVE-2026-23231netfilter: nf_tables: fix use-after-free in nf_tables_addchain()Important
MarinerCVE-2026-3381Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlibCritical
MarinerCVE-2026-0031In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Important
MarinerCVE-2026-23238romfs: check sb_set_blocksize() return valueModerate
MarinerCVE-2026-3494MariaDB Server Audit Plugin Comment Handling BypassModerate
MarinerCVE-2026-3336PKCS7_verify Certificate Chain Validation Bypass in AWS-LCImportant
MarinerCVE-2026-0032In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Important
Microsoft AuthenticatorCVE-2026-26123Microsoft Authenticator Information Disclosure VulnerabilityImportant
Microsoft Brokering File SystemCVE-2026-25167Microsoft Brokering File System Elevation of Privilege VulnerabilityImportant
Microsoft Devices Pricing ProgramCVE-2026-21536Microsoft Devices Pricing Program Remote Code Execution VulnerabilityCritical
Microsoft Edge (Chromium-based)CVE-2026-3544Chromium: CVE-2026-3544 Heap buffer overflow in WebCodecsUnknown
Microsoft Edge (Chromium-based)CVE-2026-3540Chromium: CVE-2026-3540 Inappropriate implementation in WebAudioUnknown
Microsoft Edge (Chromium-based)CVE-2026-3536Chromium: CVE-2026-3536 Integer overflow in ANGLEUnknown
Microsoft Edge (Chromium-based)CVE-2026-3538Chromium: CVE-2026-3538 Integer overflow in SkiaUnknown
Microsoft Edge (Chromium-based)CVE-2026-3545Chromium: CVE-2026-3545 Insufficient data validation in NavigationUnknown
Microsoft Edge (Chromium-based)CVE-2026-3541Chromium: CVE-2026-3541 Inappropriate implementation in CSSUnknown
Microsoft Edge (Chromium-based)CVE-2026-3543Chromium: CVE-2026-3543 Inappropriate implementation in V8Unknown
Microsoft Edge (Chromium-based)CVE-2026-3539Chromium: CVE-2026-3539 Object lifecycle issue in DevToolsUnknown
Microsoft Edge (Chromium-based)CVE-2026-3542Chromium: CVE-2026-3542 Inappropriate implementation in WebAssemblyUnknown
Microsoft Graphics ComponentCVE-2026-25169Windows Graphics Component Denial of Service VulnerabilityImportant
Microsoft Graphics ComponentCVE-2026-25180Windows Graphics Component Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2026-25168Windows Graphics Component Denial of Service VulnerabilityImportant
Microsoft Graphics ComponentCVE-2026-23668Windows Graphics Component Elevation of Privilege VulnerabilityImportant
Microsoft OfficeCVE-2026-26110Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2026-26113Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft OfficeCVE-2026-26134Microsoft Office Elevation of Privilege VulnerabilityImportant
Microsoft Office ExcelCVE-2026-26144Microsoft Excel Information Disclosure VulnerabilityCritical
Microsoft Office ExcelCVE-2026-26109Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2026-26108Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2026-26107Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2026-26112Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2026-26105Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2026-26114Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2026-26106Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
Microsoft Semantic Kernel Python SDKCVE-2026-26030GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerableImportant
Payment Orchestrator ServiceCVE-2026-26125Payment Orchestrator Service Elevation of Privilege VulnerabilityCritical
Push Message Routing ServiceCVE-2026-24282Push message Routing Service Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2026-25170Windows Hyper-V Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2026-21262SQL Server Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2026-26116SQL Server Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2026-26115SQL Server Elevation of Privilege VulnerabilityImportant
System Center Operations ManagerCVE-2026-20967System Center Operations Manager (SCOM) Elevation of Privilege VulnerabilityImportant
Windows Accessibility Infrastructure (ATBroker.exe)CVE-2026-25186Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure VulnerabilityImportant
Windows Accessibility Infrastructure (ATBroker.exe)CVE-2026-24291Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-25179Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-24293Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-25176Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-25178Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows App InstallerCVE-2026-23656Windows App Installer Spoofing VulnerabilityImportant
Windows Authentication MethodsCVE-2026-25171Windows Authentication Elevation of Privilege VulnerabilityImportant
Windows Bluetooth RFCOM Protocol DriverCVE-2026-23671Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege VulnerabilityImportant
Windows Device Association ServiceCVE-2026-24296Windows Device Association Service Elevation of Privilege VulnerabilityImportant
Windows Device Association ServiceCVE-2026-24295Windows Device Association Service Elevation of Privilege VulnerabilityImportant
Windows DWM Core LibraryCVE-2026-25189Windows DWM Core Library Elevation of Privilege VulnerabilityImportant
Windows Extensible File AllocationCVE-2026-25174Windows Extensible File Allocation Table Elevation of Privilege VulnerabilityImportant
Windows File ServerCVE-2026-24283Multiple UNC Provider Kernel Driver Elevation of Privilege VulnerabilityImportant
Windows GDICVE-2026-25190GDI Remote Code Execution VulnerabilityImportant
Windows GDI+CVE-2026-25181GDI+ Information Disclosure VulnerabilityImportant
Windows KerberosCVE-2026-24297Windows Kerberos Security Feature Bypass VulnerabilityImportant
Windows KernelCVE-2026-26132Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-24289Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-24287Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows MapUrlToZoneCVE-2026-23674MapUrlToZone Security Feature Bypass VulnerabilityImportant
Windows Mobile BroadbandCVE-2026-24288Windows Mobile Broadband Driver Remote Code Execution VulnerabilityImportant
Windows NTFSCVE-2026-25175Windows NTFS Elevation of Privilege VulnerabilityImportant
Windows Performance CountersCVE-2026-25165Performance Counters for Windows Elevation of Privilege VulnerabilityImportant
Windows Print Spooler ComponentsCVE-2026-23669Windows Print Spooler Remote Code Execution VulnerabilityImportant
Windows Projected File SystemCVE-2026-24290Windows Projected File System Elevation of Privilege VulnerabilityImportant
Windows Resilient File System (ReFS)CVE-2026-23673Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2026-26111Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2026-25173Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Routing and Remote Access Service (RRAS)CVE-2026-25172Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityImportant
Windows Shell Link ProcessingCVE-2026-25185Windows Shell Link Processing Spoofing VulnerabilityImportant
Windows SMB ServerCVE-2026-26128Windows SMB Server Elevation of Privilege VulnerabilityImportant
Windows SMB ServerCVE-2026-24294Windows SMB Server Elevation of Privilege VulnerabilityImportant
Windows System Image ManagerCVE-2026-25166Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution VulnerabilityImportant
Windows Telephony ServiceCVE-2026-25188Windows Telephony Service Elevation of Privilege VulnerabilityImportant
Windows Universal Disk Format File System Driver (UDFS)CVE-2026-23672Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege VulnerabilityImportant
Windows Win32KCVE-2026-24285Win32k Elevation of Privilege VulnerabilityImportant
WinlogonCVE-2026-25187Winlogon Elevation of Privilege VulnerabilityImportant

Πηγή: www.bleepingcomputer.com

📧
Εγγραφείτε στο Newsletter του SecNews

Τα σημαντικότερα νέα Ασφάλειας & Τεχνολογίας στο Inbox σας.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

ΑΝΑΖΗΤΗΣΗ

FOLLOW US

📧
Newsletter SecNews
Τα σημαντικότερα νέα Ασφάλειας & Τεχνολογίας στο inbox σας.

LIVE NEWS