CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The March 2026 Security Update Review

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 398

As cited

Copy frozen at (site build).

vulnerabilities

The March 2026 Security Update Review

Adobe released eight bulletins addressing 80 CVEs across multiple products including Acrobat Reader, Experience Manager, and Substance 3D tools in March 2026. Microsoft patched 84 CVEs in Windows, Office, Edge, Azure, and other components, with eight rated Critical severity and no active exploitation reported at release. Notable vulnerabilities include an Excel XSS bug exploitable by Copilot agents for data exfiltration and Office Preview Pane remote code execution issues.

Why it matters: Organizations running Adobe and Microsoft products need to prioritize Acrobat Reader (Critical bugs), Substance 3D Stager (six Critical arbitrary code execution flaws), and Microsoft Office Preview Pane vulnerabilities as immediate patching candidates to prevent potential data theft and code execution attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

The March 2026 Security Update Review

Adobe released eight bulletins addressing 80 CVEs across multiple products including Acrobat Reader, Experience Manager, and Substance 3D tools in March 2026. Microsoft patched 84 CVEs in Windows, Office, Edge, Azure, and other components, with eight rated Critical severity and no active exploitation reported at release. Notable vulnerabilities include an Excel XSS bug exploitable by Copilot agents for data exfiltration and Office Preview Pane remote code execution issues.

Why it matters: Organizations running Adobe and Microsoft products need to prioritize Acrobat Reader (Critical bugs), Substance 3D Stager (six Critical arbitrary code execution flaws), and Microsoft Office Preview Pane vulnerabilities as immediate patching candidates to prevent potential data theft and code execution attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary