logo

Microsoft Fixes Two Zero-Days in April Patch Tuesday

ID: 28894a47-7390-5cda-8a77-d34b000a4d33

STIX ID: report--28894a47-7390-5cda-8a77-d34b000a4d33

Feed Name: Infosecurity Magazine (News)

Threat Score
80/100

Date Published: 2026-04-15

Date Updated: 2026-04-22

...
...

Microsoft’s Patch Tuesday release includes multiple high-impact fixes: **CVE-2026-32201**, a SharePoint server spoofing zero-day that is being actively exploited; **CVE-2026-33825**, a Microsoft Defender elevation-of-privilege bug that has been publicly disclosed; and **CVE-2026-33824**, a critical IKEv2 remote code execution flaw (CVSS 9.8). Administrators are urged to prioritize patching internet-facing IKEv2 systems and update SharePoint and endpoints to mitigate risks of phishing, lateral movement, and full endpoint compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.