CVE-2026-21536Patch(microsoft / devices_pricing_program)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft devices_pricing_program systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • devices_pricing_program

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 32 mentions across 14 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 29 signals
  • Disclosure: 11 classified signals
  • General: 6 classified signals
  • Peaked 9d ago at 6 mentions (2026-03-11); latest day: 1
  • 32 total mentions across 14 days

Affected systems

Vendors
Products
devices_pricing_program

1 version affected across 1 product

Deep dive

Activity timeline32 mentions / 14d
02356Mentions · 2026-03-05: 1Mentions · 2026-03-06: 5Mentions · 2026-03-07: 2Mentions · 2026-03-10: 1Mentions · 2026-03-11: 6Mentions · 2026-03-12: 4Mentions · 2026-03-13: 2Mentions · 2026-03-14: 2Mentions · 2026-03-15: 1Mentions · 2026-03-20: 2Mentions · 2026-03-26: 2Mentions · 2026-03-29: 2Mentions · 2026-04-03: 1Mentions · 2026-07-25: 1Active Exploitation · 2026-03-11: 2Active Exploitation · 2026-03-14: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 3Patch / Workaround · 2026-03-12: 2Patch / Workaround · 2026-03-13: 2Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-29: 2Patch / Workaround · 2026-07-25: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-07: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 6Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 2Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-26: 2Technical Details · 2026-03-29: 2Technical Details · 2026-04-03: 1Technical Details · 2026-07-25: 103-0503-0603-0703-1003-1103-1203-1303-1403-1503-2003-2603-2904-0307-25
Signal classification4 categories
Patch
1237.5%
Disclosure
1134.4%
General
618.8%
Active Exploitation
39.4%
Referenced assets22 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-065
Disclosure3General2
2026-03-072
Disclosure1General1
2026-03-101
Patch1
2026-03-116
Active Exploitation2Disclosure2Patch2
2026-03-124
General2Patch2
2026-03-132
Patch2
2026-03-142
Active Exploitation1Disclosure1
2026-03-151
Patch1
2026-03-202
Disclosure1Patch1
2026-03-262
Disclosure1General1
2026-03-292
Patch2
2026-04-031
Disclosure1
2026-07-251
Patch1
Full discourse20 posts
  • XBOW@Xbow
    Patch

    “The vulnerability with the highest CVSS score in this month’s update is a critical remote code execution flaw in the Microsoft Devices Pricing Program. CVE-2026-21536 (CVSS score: 9.8), per Microsoft, has been fully mitigated [...] Artificial intelligence (AI)-powered autonomous vulnerability discovery platform XBOW has been credited with discovering and reporting the issue.” https://bit.ly/4s2u8vq

    Post summary

    The text reports a newly discovered critical remote code execution flaw in Microsoft Devices Pricing Program that has been fully mitigated by Microsoft, with the vulnerability discovered by AI platform XBOW.

    23441396334.1K
    10.8K followersView on X
  • AISecHub@AISecHub
    Disclosure

    XBOW has been credited with discovering the most severe vulnerability addressed in this month’s Patch Tuesday update. Among the 84 newly disclosed vulnerabilities affecting Microsoft software, XBOW uncovered CVE-2026-21536 in the Microsoft Devices Pricing Program—a critical flaw with a CVSS score of 9.8. The discovery highlights how autonomous offensive security can identify high-impact vulnerabilities early, enabling them to be fixed sooner. #Microsoft #PatchTuesday #CyberSecurity #VulnerabilityManagement #SecurityUpdates Source: https://thehackernews.com/2026/03/microsoft-patches-84-flaws-in-march.html

    Post summary

    The post announces XBOW’s discovery of CVE-2026-21536, a critical Microsoft flaw (CVSS 9.8), as part of this month’s Patch Tuesday update.

    0302042.1K
    7.9K followersView on X
  • Sentrinus@sentrinus
    Disclosure

    Critical file upload bypass hits @Microsoft 🚨 CVE-2026-21536 (CVSS 9.8) lets attackers upload anything → instant code execution. No auth needed. Zero clicks required. https://t.co/8DjPBdLuJA

    Post summary

    The tweet announces a high‑severity Microsoft vulnerability (CVE‑2026‑21536) that allows unauthenticated file uploads to trigger immediate code execution, but it does not provide evidence of active exploitation or remediation.

    1102058
    7 followersView on X
  • Vito Botta@vitobotta
    Disclosure

    First time an autonomous AI has found critical vulnerabilities in Microsoft Cloud without source code access. XBOW got credited with 3 RCEs in March Patch Tuesday, including CVE-2026-21536 - one of the most severe issues this release. The vulnerabilities were in production systems, the kind that normally take experienced researchers weeks to develop. AI-driven discovery is accelerating and it's not going away. Defenders need to move just as fast.

    Post summary

    A research group leveraged autonomous AI to discover three critical remote code execution vulnerabilities in Microsoft Cloud during Patch Tuesday, with CVE-2026-21536 highlighted as the most severe of the release.

    1001093
    907 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    ☁️ CVE-2026-21536 (MS Devices Pricing Program): Critical 9.8 unrestricted file upload RCE. Cloud-patched, but verify! https://nvd.nist.gov/vuln/detail/CVE-2026-21536

    Post summary

    CVE‑2026‑21536 is a critical 9.8 RCE via unrestricted file upload; Microsoft has applied a cloud patch, but users should verify the update.

    1001041
    492 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Patch

    🎙️ RadioCSIRT Ép.595 – Épisode Spécial du jeudi 12 mars 2026 Un seul sujet. Un cycle qui marque l'histoire des CVE : le Patch Tuesday Microsoft de mars 2026. 🔴 Microsoft Patch Tuesday – 79 vulnérabilités corrigées, deux zero-days publiquement divulgués. CVE-2026-26113 et CVE-2026-26110 : deux RCE critiques dans Microsoft Office déclenchables par simple visualisation d'un message dans le volet de prévisualisation, sans interaction utilisateur. 🔴 CVE-2026-26144 – Microsoft Excel et Copilot Agent Mode. Divulgation d'informations critique : un attaquant peut forcer Copilot à exfiltrer des données via un trafic réseau non prévu. Attaque zero-click documentée. 🔴 CVE-2026-21262 – SQL Server, élévation de privilèges jusqu'au niveau sysadmin via le réseau (CVSS 8.8). Zero-day publiquement divulgué avant correctif. CVE-2026-26127 – .NET, déni de service réseau sans authentification. 🔴 Six vulnérabilités Important signalées comme prioritaires par Cisco Talos et Tenable : Windows Graphics Component, Windows Kernel, Windows Accessibility Infrastructure, Windows SMB Server, Ancillary Function Driver for WinSock, Winlogon (découverte par Google Project Zero). 🔴 CVE-2026-21536 – CVSS 9.8 Critical. Première CVE officiellement attribuée à un agent IA autonome : XBOW, agent de penetration testing entièrement automatisé, sans accès au code source. Microsoft a corrigé côté serveur, sans action requise des utilisateurs. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-595-episode-special-patch-tuesday-microsoft-mars-2026/ 📖 Analyse complète sur le blog : https://blog.marcfredericgomez.fr/microsoft-patch-tuesday-mars-2026-79-vulnerabilites-corrigees-deux-zero-days-divulgues/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #PatchTuesday #Microsoft #CVE #ZeroDay #RCE #Windows #Office #SQLServer #Copilot #AI #XBOW #PatchManagement #VulnerabilityManagement #InfoSec #CERT #CSIRT #SOC #CISO #VOC #Patch

    Post summary

    The episode announces Microsoft’s March 2026 Patch Tuesday, summarising 79 fixed vulnerabilities—including newly disclosed zero‑days—by detailing their impact, CVSS scores, and confirming that patches have been applied server‑side with no user action required.

    0002060
    413 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 3. 6 Microsoft デバイス価格プログラムのリモートでコードが実行される脆弱性 CVE-2026-21536 Security Vulnerability リリース日: Mar 6, 2026 - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21536

    Post summary

    Microsoft announced on March 6, 2026 that CVE‑2026‑21536 is a remote code execution vulnerability in its device program, with details available on the MSRC website.

    10100146
    89 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    💳 CVE-2026-21536 (Microsoft Devices Pricing Program): 9.8 CRIT unauth RCE via unrestricted file upload. Patch: March 2026 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21536 https://nvd.nist.gov/vuln/detail/CVE-2026-21536 https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-march-2026/

    Post summary

    The tweet announces an unauthenticated RCE vulnerability (CVSS 9.8) in Microsoft’s Devices Pricing Program and confirms a patch will be released in March 2026, with links to the official advisory, NVD entry, and CrowdStrike analysis.

    1000058
    492 followersView on X
  • William Morrison@morrwillie
    Disclosure

    👀 The vulnerability with the highest CVSS score in this month's update is a critical remote code execution flaw in the Microsoft Devices Pricing Program. CVE-2026-21536 (CVSS score: 9.8). AI-powered autonomous vulnerability discovery platform XBOW has been credited with discovering and reporting the issue. Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days https://thehackernews.com/2026/03/microsoft-patches-84-flaws-in-march.html via @TheHackersNews @Xbow

    Post summary

    CVE-2026-21536 is identified as a critical remote code execution flaw in the Microsoft Devices Pricing Program, discovered by the XBOW platform, with a CVSS score of 9.8; the vulnerability is highlighted in a recent Microsoft patch release.

    0001067
    481 followersView on X
  • Eren Gezen@Eren_gzn
    Patch

    Microsoft yine yama yağdırıyor, 83 zafiyet birden. Hele şu CVE-2026-21536 RCE açığı... Kimlik doğrulaması bile istemiyor, bulutta proaktif kapatılması zorunlu hale gelmiş. Siber dünyanın bitmeyen döngüsü. #SiberGüvenlik

    Post summary

    The post announces Microsoft has issued patches for 83 vulnerabilities, including the CVE-2026-21536 remote code execution flaw, urging proactive cloud closure to mitigate risk.

    0001066
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Microsoft ❗ CVE-2026-21536 ❗ CVE-2026-21262 ❗ CVE-2026-20967 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-microsoft-7/ https://t.co/FH7ZQ7Nxqe

    Post summary

    The tweet simply lists three Microsoft CVEs and links to a source for further information, without providing technical details, exploitation evidence, or mitigation guidance.

    00001109
    6.6K followersView on X
  • Predictive AI@Predictive2033
    Disclosure

    AI is not just attacking, it's defending! 🤖 XBOW, an autonomous AI, just uncovered a critical RCE bug (CVE-2026-21536) in Microsoft's program. A major milestone for AI in #cybersecurity and #infosec. #AI #PenTesting #Vulnerability

    Post summary

    The post announces that AI tool XBOW has discovered a critical remote code execution vulnerability (CVE-2026-21536) in a Microsoft program, with no further detail on exploitation or remediation.

    0001043
    17 followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft -対象外:1 件 ・CVE-2026-26125 8.6 決済オーケストレーション サービス -CVSS 基本値が 9.8 以上のもの:1 件 ・CVE-2026-21536 9.8 マイクロソフト デバイス価格プログラム

    Post summary

    The tweet lists two new CVEs from Microsoft with their CVSS scores, providing a brief disclosure of their severity but no additional exploitation, patch, or technical details.

    1000054
    89 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Microsoft patched 83 vulnerabilities, including a critical RCE (CVE-2026-21536) fully mitigated. Two bugs disclosed: .NET DoS (CVE-2026-26127) and SQL Server privilege escalation (CVE-2026-21262). #MicrosoftUpdate #AzureSecurity #USA https://ift.tt/Rwdi9f7

    Post summary

    Microsoft released patches for 83 vulnerabilities, including a critical RCE (CVE-2026-21536), plus .NET DoS and SQL Server privilege escalation bugs, with no active exploitation or PoC mentioned.

    00010166
    3.7K followersView on X
  • kawn@kawn2020
    General

    #securityupdate #microsoft #定例外 CVE-2026-21536 Security Vulnerability 影響: リモートでコードが実行される 最大深刻度: 緊急 CVSS:3.1 9.8 / 8.5 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 悪用される可能性は非常に低い https://x.com/kawn2020/status/2030110056658915818

    Post summary

    The tweet provides a succinct disclosure of CVE‑2026‑21536, labeling it as a remote code execution vulnerability with an extreme CVSS score, while noting that active exploitation is unlikely and offering no PoC, exploit, or patch.

    1000071
    89 followersView on X
  • Beto Day@BetoDay
    Patch

    ⚠️ ALERTA DE VULNERABILIDAD 📅 24/07/2026 💥 Impacto: Ejecución de código 🔴 Severidad: Crítica 🎯 CVEs: CVE-2026-32194, CVE-2026-32191, CVE-2026-21536 Afecta a productos de Microsoft (Bing e imágenes). ¡Aplica parches oficiales! #Cybersecurity #TechNews #CVE #Infosec https://t.co/DhvxeyEdKM

    Post summary

    Alert announces three critical Microsoft CVEs affecting Bing and image services, noting that official patches have been released.

    0000084
    200 followersView on X
  • The Agent Economist@The_Agent_Econ
    General

    one hacker just found a 9.8 cvss exploit. ai agent xbow discovered cve-2026-21536. modelscope, tensorflow, keras all have critical flaws. prompt injection is a weapon. your agents are in the crosshairs. secure your bots before they get breached.

    Post summary

    The post announces the discovery of a high‑score exploit for CVE‑2026‑21536 affecting major ML frameworks, but offers no PoC, exploitation code, or patch information.

    0000063
    12 followersView on X
  • Avertium@Avertium
    Patch

    💥 FLASH NOTICE 💥 CVE-2026-21536 is a critical unauthenticated #RCE in #Microsoft Devices Pricing Program that lets attackers upload and execute malicious files on servers. Organizations should apply the security update immediately. Full report details: https://www.avertium.com/flash-notices/microsoft-devices-pricing-program-remote-code-execution-vulnerability

    Post summary

    A critical unauthenticated remote code execution vulnerability in Microsoft Devices Pricing Program is disclosed and vendors are urged to apply the patch immediately.

    0000052
    1.4K followersView on X
  • Elegant Software Sln@essrocksoftware
    Active Exploitation

    Your AI agent just got hacked through a man-in-the-middle attack exploiting Azure's CVE-2026-21536. MCP policy controls are your new defense line against agent hijacking. https://www.elegantsoftwaresolutions.com/blog/mcp-policy-controls-azure-cve-2026-21536 #VibeCoding #InfoSec https://t.co/NJbhw4naPP

    Post summary

    The tweet reports that Azure CVE‑2026‑21536 was actively exploited via a man‑in‑the‑middle attack to hijack an AI agent, and recommends MCP policy controls as a mitigating defense.

    0000031
    95 followersView on X
  • CyberSec Intel Alliance@CyberAlliance26
    Patch

    🚨 Top New Threat 🚨 (March 2026 Patch Tuesday): CVE-2026-21536 – Critical Remote Code Execution in Microsoft Devices Pricing Program (CVSS 9.8)! Unauthenticated attackers can exploit unrestricted file uploads to execute arbitrary code remotely, risking full compromise of confidentiality, integrity & availability. Remediation: Install March 2026 security updates NOW via Windows Update / Catalog (affects the cloud-backed pricing service for devices & partners). Patch or get pwned! #CyberSecurity #PatchTuesday #ZeroDay

    Post summary

    The post alerts readers to CVE-2026-21536, a critical remote code execution flaw in Microsoft Devices Pricing Program, and urges immediate installation of the March 2026 security updates.

    0000052
    24 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftdevices_pricing_program---

Explore more