logo

Wormable Bugs: Microsoft April 2026 Patch Tuesday Fixes Two “Zero-Interaction” RCE Flaws

ID: 86c65106-95ba-56e8-97fe-781fd9cae684

STIX ID: report--86c65106-95ba-56e8-97fe-781fd9cae684

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ddos

...
...

**Urgent Windows wormable vulnerabilities:** Microsoft’s April 2026 Patch Tuesday fixes two high-risk, wormable RCE vulnerabilities—CVE-2026-33827 (TCP/IP stack, CVSS 8.1; requires IPv6+IPSec and a race condition) and CVE-2026-33824 (IKEv2 service extensions, CVSS 9.8)—which allow unauthenticated attackers to propagate across networks without user interaction; administrators are urged to prioritize patches and block UDP 500/4500 at the perimeter to mitigate exploitation and lateral spread.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.