Microsoft Patch Tuesday – March 2021 Edition

Microsoft Patch Tuesday – March 2021 Edition

Wizard Cyber has produced the below information sheet to get you updated with Microsofts Patch Tuesday and the latest information.

Link to Microsoft Release Notes: CLICK HERE

 

What is Microsoft Patch Tuesday?

Patch Tuesday, the colloquial term for Microsoft’s Update Tuesday that falls on the second Tuesday of every month. That is when Microsoft rolls out patch updates to improve the security of Microsoft applications. Coinciding with the Patch Tuesday it is also a general trend for the roll out of patch updates for other third-party applications that include Adobe and Mozilla, among many others.

Patch Tuesday Latest

Another Patch Tuesday (2021-Mar) is upon us and with this month comes a whopping 122 CVEs.  As usual, Windows tops the list of the most patched product. However, this month it’s browser vulnerabilities taking second place, outnumbering Office vulnerabilities 3:1! Lastly, the Exchange Server vulnerabilities this month are not to be ignored as more than half of them have been seen exploited in the wild.

Exchange Server Vulnerabilities

Earlier this month Microsoft released out of band updates for Exchange Server. These critical updates fixed a number of publicly exploited vulnerabilities, but not before attackers were able to compromise over 30,000 internet-facing instances.

Yesterday, Microsoft issued an additional set of patches for older, unsupported versions of the Exchange Server. This allows customers who have not been able to update to the most recent version of Exchange the ability to defend against these widespread exploit attempts.

If you administer an Exchange Server, stop reading this blog and go patch these systems!

Patch those Windows systems!

Almost half of the newly announced vulnerabilities this month affect components of Windows itself. Some major highlights include:

Browser Vulnerabilities

Since going end-of-life in November 2020, we haven’t seen any Internet Explorer patches from Microsoft. However, this month Microsoft has made two new updates available: CVE-2021-27085 and CVE-2021-26411. CVE-2021-26411 has been exploited in the wild, so don’t delay applying patches if IE is still in your environment.

The majority of the browser vulnerabilities announced this month affect Microsoft Edge on Chromium. These patches are courtesy of vulnerabilities being fixed upstream in the Chromium project.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation