MONTHLY FALLOUT REPORT
MARCH 2026 FALLOUT
83 vulnerabilities addressed. While the numbers look tame compared to February, the silent preparation for Secure Boot certificate rotation is the real "slow-burn" threat. Admins are reporting authentication latencies as the update signals begin hitting the fleet.
83
VULNERABILITIES
2
ZERO-DAYS EXPLOITED
11
CRITICAL RCES
1
OOB ISSUED
Fallout Timeline
Initial Release — Patch Tuesday Day 0
March 10, 2026 — Microsoft released 83 vulnerabilities, including two publicly disclosed zero-days (CVE-2026-21262 and CVE-2026-26127). Focus remains on Secure Boot certificate rotation and preventing COM object lockouts in WDAC.
72 Hours Out +3 Days
Kerberos Auth Latency: Enterprise environments are reporting a significant "auth-lag." Authentications are taking ~30% longer to process per-minute, a side effect of PAC validation hardening aimed at preventing silver ticket attacks.
OOB Release: Microsoft issued KB5084597 (March 13) to fix an emergency RCE vulnerability in the Routing and Remote Access Service (RRAS) management tool affecting 25H2/24H2 systems.
2 Weeks Out +14 Days
Firmware Lockouts: Reports of "Windows Boot Manager blocked by current security policy" have spiked on legacy UEFI systems. This is confirmed as a mismatch between staged revocations and outdated firmware trust anchors.
The Samsung Glitch: A widely reported issue where Samsung Galaxy Book owners lost access to their C: drive was officially traced to a bug in the Samsung Galaxy Connect app, not the Windows update itself.
Application Instability: Widespread reports of audio driver crashes affecting VoIP tools like 3CX and Teams, resulting in "No Audio Device Found" errors after the March LCU reboot.