logo

Patch Tuesday: April 2026 (Expel’s version)

ID: 9358fff9-a022-5adc-9d50-ef738d2d9f11

STIX ID: report--9358fff9-a022-5adc-9d50-ef738d2d9f11

Feed Name: Expel Blog

Threat Score
80/100

Date Published: 2026-04-14

Date Updated: 2026-04-27

...
...

April 2026 Patch Tuesday covers 167 CVEs (including two zero-days) with notable items being a SharePoint spoofing vulnerability (CVE-2026-32201) observed exploited in the wild and a Microsoft Defender elevation-of-privilege (CVE-2026-33825); the report also highlights the Axios NPM supply-chain compromise where malicious postinstall hooks auto-executed and exfiltrated credentials, urging organizations to treat affected systems as compromised and to extend vulnerability management to include dependency integrity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.