As cited
Copy frozen at (site build).
vulnerabilities
The March 2026 Security Update Review
Adobe released eight bulletins addressing 80 CVEs across multiple products including Acrobat Reader, Experience Manager, and Substance 3D tools in March 2026. Microsoft patched 84 CVEs in Windows, Office, Edge, Azure, and other components, with eight rated Critical severity and no active exploitation reported at release. Notable vulnerabilities include an Excel XSS bug exploitable by Copilot agents for data exfiltration and Office Preview Pane remote code execution issues.
Why it matters: Organizations running Adobe and Microsoft products need to prioritize Acrobat Reader (Critical bugs), Substance 3D Stager (six Critical arbitrary code execution flaws), and Microsoft Office Preview Pane vulnerabilities as immediate patching candidates to prevent potential data theft and code execution attacks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
The March 2026 Security Update Review
Adobe released eight bulletins addressing 80 CVEs across multiple products including Acrobat Reader, Experience Manager, and Substance 3D tools in March 2026. Microsoft patched 84 CVEs in Windows, Office, Edge, Azure, and other components, with eight rated Critical severity and no active exploitation reported at release. Notable vulnerabilities include an Excel XSS bug exploitable by Copilot agents for data exfiltration and Office Preview Pane remote code execution issues.
Why it matters: Organizations running Adobe and Microsoft products need to prioritize Acrobat Reader (Critical bugs), Substance 3D Stager (six Critical arbitrary code execution flaws), and Microsoft Office Preview Pane vulnerabilities as immediate patching candidates to prevent potential data theft and code execution attacks.
- Source published
- First seen by Cybersecurity Tracker