MONTHLY FALLOUT REPORT

MARCH 2026 FALLOUT

83 vulnerabilities addressed. While the numbers look tame compared to February, the silent preparation for Secure Boot certificate rotation is the real "slow-burn" threat. Admins are reporting authentication latencies as the update signals begin hitting the fleet.

DAMAGE RATING

83

VULNERABILITIES

2

ZERO-DAYS EXPLOITED

11

CRITICAL RCES

1

OOB ISSUED

Fallout Timeline

Initial Release — Patch Tuesday Day 0

March 10, 2026 — Microsoft released 83 vulnerabilities, including two publicly disclosed zero-days (CVE-2026-21262 and CVE-2026-26127). Focus remains on Secure Boot certificate rotation and preventing COM object lockouts in WDAC.

72 Hours Out +3 Days

Kerberos Auth Latency: Enterprise environments are reporting a significant "auth-lag." Authentications are taking ~30% longer to process per-minute, a side effect of PAC validation hardening aimed at preventing silver ticket attacks.

OOB Release: Microsoft issued KB5084597 (March 13) to fix an emergency RCE vulnerability in the Routing and Remote Access Service (RRAS) management tool affecting 25H2/24H2 systems.

2 Weeks Out +14 Days

Firmware Lockouts: Reports of "Windows Boot Manager blocked by current security policy" have spiked on legacy UEFI systems. This is confirmed as a mismatch between staged revocations and outdated firmware trust anchors.

The Samsung Glitch: A widely reported issue where Samsung Galaxy Book owners lost access to their C: drive was officially traced to a bug in the Samsung Galaxy Connect app, not the Windows update itself.

Application Instability: Widespread reports of audio driver crashes affecting VoIP tools like 3CX and Teams, resulting in "No Audio Device Found" errors after the March LCU reboot.