Patch Tuesday cycleMarch 2026 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

March 2026 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 86 operational patch records link 167 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

86Patch recordsStable operational entries, not CVE duplicates
167Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
0Accelerated actionsNo accelerated action in this view
0Revised entriesCanonical history remains visible

March 2026 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
86 matching recordsPage 1 of 5
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB26-05 · Updated 2026-03-10
Product and releaseAdobe Commerce2.4.9‑beta1 for 2.4.9‑alpha3, 2.4.8‑p4 for 2.4.8‑p3 and earlier, 2.4.7‑p9 for 2.4.7‑p8 and earlier, 2.4.6‑p14 for 2.4.6‑p13 and earlier, 2.4.5‑p16 for 2.4.5‑p15 and earlier, 2.4.4‑p17 for 2.4.4‑p16 and earlier, 1.5.3‑beta1 for 1.5.3‑alpha3, 1.5.2‑p4 for 1.5.2‑p3 and earlier, 1.4.2‑p9 for 1.4.2‑p8 and earlier, 1.3.5‑p14 for 1.3.5‑p13 and earlier, 1.3.4‑p16 for 1.3.4‑p15 and earlier, 1.3.3‑p17 for 1.3.3‑p16 and earlier, 2.4.9‑beta1 for 2.4.9‑alpha3, 2.4.8‑p4 for 2.4.8‑p3 and earlier, 2.4.7‑p9 for 2.4.7‑p8 and earlier, 2.4.6‑p14 for 2.4.6‑p13 and earlier, 2.4.5‑p16 for 2.4.5‑p15 and earlier
Review linked CVEs (19) No confirmed exploitation stated

Operational summary

Adobe published APSB26-05 on Patch Tuesday for Adobe Commerce. The bulletin links 19 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-05
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.7; Adobe priority 2

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager to the fixed Adobe releaseAPSB26-24 · Updated 2026-03-10
Product and releaseAdobe Experience ManagerAEM Cloud Service (CS) Release 2026.02, 6.5 LTS Service Pack 2, 6.5 Service Pack 24
Review linked CVEs (33) No confirmed exploitation stated

Operational summary

Adobe published APSB26-24 on Patch Tuesday for Adobe Experience Manager. The bulletin links 33 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-24
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.4; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Painter to the fixed Adobe releaseAPSB26-25 · Updated 2026-03-10
Product and releaseAdobe Substance 3D Painter11.1.3
Review linked CVEs (9) No confirmed exploitation stated

Operational summary

Adobe published APSB26-25 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 9 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-25
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.5; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (9)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe DNG SDK to the fixed Adobe releaseAPSB26-30 · Updated 2026-03-10
Product and releaseAdobe DNG SDKDNG SDK 1.7.1 build 2502
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-30 on Patch Tuesday for Adobe DNG SDK. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-30
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Acrobat Reader to the fixed Adobe releaseAPSB26-26 · Updated 2026-03-10
Product and releaseAdobe Acrobat ReaderFixed release detail requires source review
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB26-26 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-26
Platform
See Adobe bulletin
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB26-18 · Updated 2026-03-10
Product and releaseAdobe Illustrator29.8.5 and above, 30.2 and above
Review linked CVEs (7) No confirmed exploitation stated

Operational summary

Adobe published APSB26-18 on Patch Tuesday for Adobe Illustrator. The bulletin links 7 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-18
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (7)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Premiere Pro to the fixed Adobe releaseAPSB26-28 · Updated 2026-03-10
Product and releaseAdobe Premiere Pro26.0, 25.6 LTS
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-28 on Patch Tuesday for Adobe Premiere Pro. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-28
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft Authenticator for AndroidMSRC-2026-03-apps-release-notes · Updated 2026-03-10
Product and releaseMicrosoft Authenticator for Android6.2511.7533
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Authenticator for Android.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-apps-release-notes
Platform
Apps
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft Authenticator for IOSMSRC-2026-03-apps-release-notes · Updated 2026-03-10
Product and releaseMicrosoft Authenticator for IOS6.8.40
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Authenticator for IOS.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-apps-release-notes
Platform
Apps
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Windows Admin Center in Azure PortalMSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseWindows Admin Center in Azure Portal2.6.4
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Admin Center in Azure Portal.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure IoT ExplorerMSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseAzure IoT Explorer0.15.13, 0.15.14
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Azure IoT Explorer.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft Azure AD SSH Login extension for LinuxMSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseMicrosoft Azure AD SSH Login extension for Linux1.0.033370002
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Azure AD SSH Login extension for Linux.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Linux Virtual Machines with Azure Diagnostics extensionMSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseAzure Linux Virtual Machines with Azure Diagnostics extension2.1.24
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Linux Virtual Machines with Azure Diagnostics extension.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Arc Enabled Servers - Azure Connected Machine AgentMSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseArc Enabled Servers - Azure Connected Machine Agent1.61
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Arc Enabled Servers - Azure Connected Machine Agent.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure MCP Server Tools 2.0.0 (NuGet)MSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseAzure MCP Server Tools 2.0.0 (NuGet)2.0.0-beta.17
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure MCP Server Tools 2.0.0 (NuGet).

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure MCP Server Tools 2.0.0 (npm)MSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseAzure MCP Server Tools 2.0.0 (npm)2.0.0-beta.17
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure MCP Server Tools 2.0.0 (npm).

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure MCP Server Tools 2.0.0 (PyPi)MSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseAzure MCP Server Tools 2.0.0 (PyPi)2.0.0-beta.17
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure MCP Server Tools 2.0.0 (PyPi).

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure MCP Server Tools 1.0.0 (NuGet)MSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseAzure MCP Server Tools 1.0.0 (NuGet)1.0.2
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure MCP Server Tools 1.0.0 (NuGet).

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure MCP Server Tools 1.0.0 (npm)MSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseAzure MCP Server Tools 1.0.0 (npm)1.0.2
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure MCP Server Tools 1.0.0 (npm).

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Automation Hybrid Worker Windows ExtensionMSRC-2026-03-azure-release-notes · Updated 2026-03-10
Product and releaseAzure Automation Hybrid Worker Windows Extension1.3.74
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Automation Hybrid Worker Windows Extension.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-03-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0