Microsoft’s April 2026 Patch Tuesday Addresses 163 CVEs (CVE-2026-32201)
ID: b1848f66-606b-587b-a9eb-a3649fdfd382
STIX ID: report--b1848f66-606b-587b-a9eb-a3649fdfd382
Feed Name: Security Boulevard
Microsoft's April 2026 Patch Tuesday patched 163 CVEs across a wide range of Windows and Microsoft products, including eight critical and multiple important vulnerabilities; the release includes two zero-days (one reportedly exploited in the wild) and a publicly disclosed exploit. Notable issues include a SharePoint spoofing zero-day (CVE-2026-32201) exploited in the wild, a publicly disclosed Microsoft Defender EoP (CVE-2026-33825, linked to the BlueHammer exploit), and a critical unauthenticated IKEv2 RCE (CVE-2026-33824, CVSS 9.8). Elevation-of-privilege flaws comprised the largest share of fixes, and Microsoft and Tenable recommend immediate patching and scanning to mitigate active and likely exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
