April Patch Tuesday fixes two zero-days, including one under active attack
ID: 0aaed7b2-7419-5694-8c36-35bfd9894de2
STIX ID: report--0aaed7b2-7419-5694-8c36-35bfd9894de2
Feed Name: Malwarebytes Blog
Threat Score
This Patch Tuesday advisory reports 167 security fixes including two zero-day vulnerabilities — CVE-2026-32201 (Microsoft SharePoint spoofing, actively exploited) and CVE-2026-33825 (Microsoft Defender elevation-of-privilege, publicly disclosed) — and warns of remote-code-execution fixes in Office; it urges immediate application of Microsoft updates and provides step-by-step Windows Update guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
