logo

Microsoft’s April 2026 Patch Tuesday Addresses 163 CVEs (CVE-2026-32201)

ID: b1848f66-606b-587b-a9eb-a3649fdfd382

STIX ID: report--b1848f66-606b-587b-a9eb-a3649fdfd382

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Research Special Operations

...
...

Microsoft's April 2026 Patch Tuesday patched 163 CVEs across a wide range of Windows and Microsoft products, including eight critical and multiple important vulnerabilities; the release includes two zero-days (one reportedly exploited in the wild) and a publicly disclosed exploit. Notable issues include a SharePoint spoofing zero-day (CVE-2026-32201) exploited in the wild, a publicly disclosed Microsoft Defender EoP (CVE-2026-33825, linked to the BlueHammer exploit), and a critical unauthenticated IKEv2 RCE (CVE-2026-33824, CVSS 9.8). Elevation-of-privilege flaws comprised the largest share of fixes, and Microsoft and Tenable recommend immediate patching and scanning to mitigate active and likely exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.