Microsoft Patch Tuesday for April 2026
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-32225 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2026-23666 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2026-32155 +1 in the same advisory: …27906 | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2026-33826 +1 in the same advisory: …27913 | Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. NVD description · AI analysis pending | 8.0 group max | <1% |
| — | ||
| CVE-2026-32152 +1 in the same advisory: …32154 | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-32157 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2026-32162 | Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally. Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally. NVD description · AI analysis pending | 8.4 | 2% |
| — | ||
| CVE-2026-32190 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 8.4 | <1% |
| — | ||
| CVE-2026-32201 | Improper Input Validation Spoofing Vulnerability in Microsoft SharePoint Server Microsoft SharePoint Server contains an improper input validation flaw (CWE-20) that can be triggered by an unauthenticated, network-based attacker submitting crafted input to the server. Successful exploitation allows the attacker to perform spoofing over the network, impersonating a trusted user or source within SharePoint; detailed impact mechanics have not been published and no CVSS score or public proof-of-concept is available. Any organization running on-premises Microsoft SharePoint Server is potentially affected, and the available data does not specify affected version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-14, indicating evidence of active exploitation, and EPSS assigns a 42.8% probability of exploitation within 30 days (99th percentile). Ransomware association is currently unknown. Do: Apply Microsoft's security updates for SharePoint Server per the vendor advisory as soon as possible, and identify your SharePoint Server versions and builds since specific affected ranges are not provided here. Given the KEV listing, federal agencies must apply the vendor mitigations, follow applicable BOD 22-01 cloud guidance, or discontinue use by the established deadline. Until patched, limit network exposure of SharePoint servers and review authentication and access logs for signs of impersonation or spoofing activity. | 6.5 | 43% | KEV |
| masslikely on the order of 100,000+ on-premises SharePoint Server installations, of which tens of thousands are directly internet-exposed | |
| CVE-2026-32202 | Spoofing Flaw in Windows Shell (CVE-2026-32202) Actively Exploited A protection mechanism in the Windows Shell fails (CWE-693), allowing an unauthorized attacker to perform spoofing against the shell over a network. Per the CVSS vector, the attack is network-based, requires no privileges or special conditions, but does require the targeted user to interact with attacker-supplied content. The impact is limited to confidentiality: an attacker can misrepresent information presented through the Windows Shell, gaining a spoofing foothold rather than code execution, privilege escalation, or persistence. Any organization running the affected Windows 10, Windows 11, or Windows Server builds is exposed, which effectively means most Windows estates. Microsoft has confirmed active exploitation, CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-04-28, and a fix shipped in Microsoft's April 2026 Patch Tuesday release. Do: Apply Microsoft's April 2026 security updates to all affected Windows 10, Windows 11, and Windows Server hosts as a priority; the flaw is on CISA's KEV catalog, so U.S. federal agencies must patch within BOD 22-01 timelines or apply vendor-recommended mitigations. Until patched, note that exploitation requires user interaction with spoofed shell content, so user awareness about verifying shell-rendered information is a partial mitigations. No public PoC is known, but confirmed in-the-wild exploitation warrants prioritizing user-facing and internet-reachable systems for patching. | 4.3 | 64% | KEV |
| mass~1 billion+ Windows devices (affected builds span all supported Windows 10 and Windows 11 desktops plus Windows Server 2012-2022) | |
| CVE-2026-33824 | Unauthenticated Double-Free RCE in Microsoft Windows IKE Extension A double-free memory-corruption flaw (CWE-415) in the Microsoft Windows Internet Key Exchange (IKE) service extension allows a remote, unauthenticated attacker to trigger the bug with crafted network traffic, with no privileges or user interaction required. Successful exploitation yields remote code execution with full system impact, reflected in the critical 9.8 CVSS score (high confidentiality, integrity, and availability). The vulnerable IKE component is present in Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, and 2022 (including 23H2), which ship it as a built-in feature. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-18, and security reporting confirms it is being actively exploited in the wild, though ransomware use is not yet confirmed. No public proof-of-concept is known, but the high EPSS score (72.7%, 99th percentile) signals a very strong likelihood of imminent or ongoing exploitation. Do: Apply Microsoft's security updates for CVE-2026-33824 to all affected Windows 10, Windows 11, and Windows Server releases, prioritizing internet-exposed systems where IKE/VPN is reachable (UDP 500/4500), per BOD 26-04 requirements. Organizations unable to patch promptly should restrict or discontinue use of exposed IKE/VPN services on affected hosts until updated. Triage VPN endpoints and remote-access servers for crashes or suspicious IKE traffic given confirmed in-the-wild exploitation. | 9.8 | 73% | KEV |
| masswell over 1B Windows devices include the built-in IKE extension; internet-exposed VPN/IKE endpoints plausibly number in the hundreds of thousands | |
| CVE-2026-33825 | Local Privilege Escalation in Microsoft Defender Antimalware Platform CVE-2026-33825 is an insufficient granularity of access control flaw (CWE-1220) in Microsoft Defender Antimalware Platform that allows an authorized attacker to elevate privileges locally. It is triggered by an attacker who already holds a low-privileged foothold on a machine running Defender, with no user interaction required. Successful exploitation has high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8), granting elevated local rights that facilitate defense evasion, persistence, or ransomware activity. Any organization running Microsoft Defender on Windows endpoints and servers is potentially affected. The flaw is actively exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-22 with ransomware use confirmed, and is one of three Microsoft Defender zero-days reported as exploited, two of which were still unpatched at the time of reporting. Do: Apply Microsoft's April 2026 Patch Tuesday updates for the Defender Antimalware Platform (platform/security intelligence updates) per vendor instructions, consistent with CISA BOD 22-01 timelines for KEV entries, and note reports that two of the three exploited Defender zero-days were still unpatched, so monitor for follow-up fixes. Prioritize patching internet-reachable and high-value Windows hosts, and hunt for signs of local privilege escalation and ransomware precursor activity on systems that cannot be updated immediately. | 7.8 | 7% | KEV ransomware |
| masshundreds of millions of Windows endpoints and servers (Defender is the default antimalware on Windows) |
Full article865 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, April 14, 2026 16:27
Microsoft has released its monthly security update for April 2026, which includes 165 vulnerabilities affecting a wide range of products, including eight Microsoft marked as “critical.”
CVE-2026-23666 is a critical Denial of Service (DoS) vulnerability that affects the .NET framework. Successful exploitation could allow the attacker to deny service over the network.
CVE-2026-32157 is a critical use after free vulnerability in the Remote Desktop Client that results in code execution. Attack requires an authorized user on the client to connect to a malicious server, which could result in code execution on the client.
CVE-2026-32190 is a critical user after free vulnerability in Microsoft Office that can result in local code execution. Attacker is remote but attack is carried out locally. Code from the local machine needs to be executed to exploit the vulnerability.
CVE-2026-33114 is a critical untrusted pointer deference vulnerability in Microsoft Office Word that could allow the attacker to execute code locally. Code from the local machine needs to be executed to exploit this vulnerability.
CVE-2026-33115 is a critical use after free vulnerability in Microsoft Office word that can result in local code execution. Similar to CVE-2026-33114 and CVE-2026-32190 the attacker is remote, but code needs to be executed from the local machine to exploit the vulnerability.
CVE-2026-33824 is a critical double free vulnerability in the Widows Internet Key Exchange (IKE) extension, allowing remote code execution. An unauthenticated attacker can send specially crafted packets to a Windows machine with IKE version 2 enabled to potentially enable remote code execution. Additional mitigations can include blocking inbound traffic on UDP ports 500 and 4500 if IKE is not in use.
CVE-2026-33826 is a critical improper input validation in Windows Active Directory that can result in code execution over an adjacent network. Requires an authenticated attacker to send specially crafted RPC calls to an RPC host. Can result in remote code execution. Note that successful exploitation requires the attacker be in the same restricted Active Directory domain as the target system.
CVE-2026-33827 is a critical race condition vulnerability in Windows TCP/IP that can result in remote code execution. Successful exploitation requires the attacker to win a race condition along with additional actions prior to exploitation to prepare the target environment. An unauthenticated actor can send specially crafted IPv6 packets to a Windows node where IPSec is enabled to potentially achieve remote code execution.
CVE-2026-32201 is an important improper input validation vulnerability in Microsoft Office SharePoint that can allow an unauthorized user to perform spoofing. An attacker that successfully exploits this vulnerability could view some sensitive information and make changes to disclosed information. This vulnerability has already been detected as being exploited in the wild.
The majority of the remaining vulnerabilities are labeled as important with a two moderate and one low vulnerability also being patched. Talos would like to highlight the several additional important vulnerabilities that Microsoft has deemed as “more likely” to be exploited.
· CVE-2026-0390 - UEFI Secure Boot Security Feature Bypass Vulnerability
· CVE-2026-26151 - Remote Desktop Spoofing Vulnerability
· CVE-2026-26169 - Windows Kernel Memory Information Disclosure Vulnerability
· CVE-2026-26173 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
· CVE-2026-26177 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
· CVE-2026-26182 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
· CVE-2026-27906 - Windows Hello Security Feature Bypass Vulnerability
· CVE-2026-27908 - Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability
· CVE-2026-27909 - Windows Search Service Elevation of Privilege Vulnerability
· CVE-2026-27913 - Windows BitLocker Security Feature Bypass Vulnerability
· CVE-2026-27914 - Microsoft Management Console Elevation of Privilege Vulnerability
· CVE-2026-27921 - Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability
· CVE-2026-27922 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
· CVE-2026-32070 - Windows Common Log File System Driver Elevation of Privilege Vulnerability
· CVE-2026-32075 - Windows UPnP Device Host Elevation of Privilege Vulnerability
· CVE-2026-32093 - Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
· CVE-2026-32152 - Desktop Window Manager Elevation of Privilege Vulnerability
· CVE-2026-32154 - Desktop Window Manager Elevation of Privilege Vulnerability
· CVE-2026-32155 - Desktop Window Manager Elevation of Privilege Vulnerability
· CVE-2026-32162 - Windows COM Elevation of Privilege Vulnerability
· CVE-2026-32202 - Windows Shell Spoofing Vulnerability
· CVE-2026-32225 - Windows Shell Security Feature Bypass Vulnerability
· CVE-2026-33825 - Microsoft Defender Elevation of Privilege Vulnerability
A complete list of all other vulnerabilities Microsoft disclosed this month is available on its update page. In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.
The rules included in this release that protect against the exploitation of many of these vulnerabilities are: 1:65902-1:65903, 1:66242-1:66251, 1:66259-1:66260, 1:66264-1:66267, 1:66275-1:66276
The following Snort 3 rules are also available: 1:301398, 1:301468-1:3101472, 1:301475, 1:301477-1:301478, 1:301480
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-april-2026/