ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-32225
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

NVD description · AI analysis pending
8.8
group max
1%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
CVE-2026-23666
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.

Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.

NVD description · AI analysis pending
7.51%
  • microsoft .net framework
CVE-2026-32155
+1 in the same advisory: …27906
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.8
group max
<1%
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • microsoft windows 11 23h2
  • +1 more
CVE-2026-33826
+1 in the same advisory: …27913
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

NVD description · AI analysis pending
8.0
group max
<1%
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
  • +1 more
CVE-2026-32152
+1 in the same advisory: …32154
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 11 23h2
  • microsoft windows 11 24h2
  • microsoft windows 11 25h2
  • +1 more
CVE-2026-32157
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.8<1%
  • microsoft remote desktop client
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2026-32162
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.

NVD description · AI analysis pending
8.42%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
CVE-2026-32190
+2 in the same advisory: …33114 …33115
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
8.4<1%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
CVE-2026-32201
Improper Input Validation Spoofing Vulnerability in Microsoft SharePoint Server

Microsoft SharePoint Server contains an improper input validation flaw (CWE-20) that can be triggered by an unauthenticated, network-based attacker submitting crafted input to the server. Successful exploitation allows the attacker to perform spoofing over the network, impersonating a trusted user or source within SharePoint; detailed impact mechanics have not been published and no CVSS score or public proof-of-concept is available. Any organization running on-premises Microsoft SharePoint Server is potentially affected, and the available data does not specify affected version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-14, indicating evidence of active exploitation, and EPSS assigns a 42.8% probability of exploitation within 30 days (99th percentile). Ransomware association is currently unknown.

Do: Apply Microsoft's security updates for SharePoint Server per the vendor advisory as soon as possible, and identify your SharePoint Server versions and builds since specific affected ranges are not provided here. Given the KEV listing, federal agencies must apply the vendor mitigations, follow applicable BOD 22-01 cloud guidance, or discontinue use by the established deadline. Until patched, limit network exposure of SharePoint servers and review authentication and access logs for signs of impersonation or spoofing activity.

6.543% KEV
  • Microsoft SharePoint Server
masslikely on the order of 100,000+ on-premises SharePoint Server installations, of which tens of thousands are directly internet-exposed
CVE-2026-32202
Spoofing Flaw in Windows Shell (CVE-2026-32202) Actively Exploited

A protection mechanism in the Windows Shell fails (CWE-693), allowing an unauthorized attacker to perform spoofing against the shell over a network. Per the CVSS vector, the attack is network-based, requires no privileges or special conditions, but does require the targeted user to interact with attacker-supplied content. The impact is limited to confidentiality: an attacker can misrepresent information presented through the Windows Shell, gaining a spoofing foothold rather than code execution, privilege escalation, or persistence. Any organization running the affected Windows 10, Windows 11, or Windows Server builds is exposed, which effectively means most Windows estates. Microsoft has confirmed active exploitation, CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-04-28, and a fix shipped in Microsoft's April 2026 Patch Tuesday release.

Do: Apply Microsoft's April 2026 security updates to all affected Windows 10, Windows 11, and Windows Server hosts as a priority; the flaw is on CISA's KEV catalog, so U.S. federal agencies must patch within BOD 22-01 timelines or apply vendor-recommended mitigations. Until patched, note that exploitation requires user interaction with spoofed shell content, so user awareness about verifying shell-rendered information is a partial mitigations. No public PoC is known, but confirmed in-the-wild exploitation warrants prioritizing user-facing and internet-reachable systems for patching.

4.364% KEV
  • microsoft Windows 10 1607
  • microsoft Windows 10 1809
  • microsoft Windows 10 21H2
  • +9 more
mass~1 billion+ Windows devices (affected builds span all supported Windows 10 and Windows 11 desktops plus Windows Server 2012-2022)
CVE-2026-33824
Unauthenticated Double-Free RCE in Microsoft Windows IKE Extension

A double-free memory-corruption flaw (CWE-415) in the Microsoft Windows Internet Key Exchange (IKE) service extension allows a remote, unauthenticated attacker to trigger the bug with crafted network traffic, with no privileges or user interaction required. Successful exploitation yields remote code execution with full system impact, reflected in the critical 9.8 CVSS score (high confidentiality, integrity, and availability). The vulnerable IKE component is present in Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, and 2022 (including 23H2), which ship it as a built-in feature. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-18, and security reporting confirms it is being actively exploited in the wild, though ransomware use is not yet confirmed. No public proof-of-concept is known, but the high EPSS score (72.7%, 99th percentile) signals a very strong likelihood of imminent or ongoing exploitation.

Do: Apply Microsoft's security updates for CVE-2026-33824 to all affected Windows 10, Windows 11, and Windows Server releases, prioritizing internet-exposed systems where IKE/VPN is reachable (UDP 500/4500), per BOD 26-04 requirements. Organizations unable to patch promptly should restrict or discontinue use of exposed IKE/VPN services on affected hosts until updated. Triage VPN endpoints and remote-access servers for crashes or suspicious IKE traffic given confirmed in-the-wild exploitation.

9.873% KEV
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • Microsoft Windows 10 21H2
  • +9 more
masswell over 1B Windows devices include the built-in IKE extension; internet-exposed VPN/IKE endpoints plausibly number in the hundreds of thousands
CVE-2026-33825
Local Privilege Escalation in Microsoft Defender Antimalware Platform

CVE-2026-33825 is an insufficient granularity of access control flaw (CWE-1220) in Microsoft Defender Antimalware Platform that allows an authorized attacker to elevate privileges locally. It is triggered by an attacker who already holds a low-privileged foothold on a machine running Defender, with no user interaction required. Successful exploitation has high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8), granting elevated local rights that facilitate defense evasion, persistence, or ransomware activity. Any organization running Microsoft Defender on Windows endpoints and servers is potentially affected. The flaw is actively exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-22 with ransomware use confirmed, and is one of three Microsoft Defender zero-days reported as exploited, two of which were still unpatched at the time of reporting.

Do: Apply Microsoft's April 2026 Patch Tuesday updates for the Defender Antimalware Platform (platform/security intelligence updates) per vendor instructions, consistent with CISA BOD 22-01 timelines for KEV entries, and note reports that two of the three exploited Defender zero-days were still unpatched, so monitor for follow-up fixes. Prioritize patching internet-reachable and high-value Windows hosts, and hunt for signs of local privilege escalation and ransomware precursor activity on systems that cannot be updated immediately.

7.87% KEV ransomware
  • Microsoft Defender Antimalware Platform
masshundreds of millions of Windows endpoints and servers (Defender is the default antimalware on Windows)
Full article865 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, April 14, 2026 16:27

Microsoft has released its monthly security update for April 2026, which includes 165 vulnerabilities affecting a wide range of products, including eight Microsoft marked as “critical.” 

CVE-2026-23666 is a critical Denial of Service (DoS) vulnerability that affects the .NET framework. Successful exploitation could allow the attacker to deny service over the network.

CVE-2026-32157 is a critical use after free vulnerability in the Remote Desktop Client that results in code execution. Attack requires an authorized user on the client to connect to a malicious server, which could result in code execution on the client. 

CVE-2026-32190 is a critical user after free vulnerability in Microsoft Office that can result in local code execution. Attacker is remote but attack is carried out locally.  Code from the local machine needs to be executed to exploit the vulnerability. 

CVE-2026-33114 is a critical untrusted pointer deference vulnerability in Microsoft Office Word that could allow the attacker to execute code locally. Code from the local machine needs to be executed to exploit this vulnerability.

CVE-2026-33115 is a critical use after free vulnerability in Microsoft Office word that can result in local code execution. Similar to CVE-2026-33114 and CVE-2026-32190 the attacker is remote, but code needs to be executed from the local machine to exploit the vulnerability.

CVE-2026-33824 is a critical double free vulnerability in the Widows Internet Key Exchange (IKE) extension, allowing remote code execution. An unauthenticated attacker can send specially crafted packets to a Windows machine with IKE version 2 enabled to potentially enable remote code execution. Additional mitigations can include blocking inbound traffic on UDP ports 500 and 4500 if IKE is not in use.

CVE-2026-33826 is a critical improper input validation in Windows Active Directory that can result in code execution over an adjacent network. Requires an authenticated attacker to send specially crafted RPC calls to an RPC host. Can result in remote code execution. Note that successful exploitation requires the attacker be in the same restricted Active Directory domain as the target system.

CVE-2026-33827 is a critical race condition vulnerability in Windows TCP/IP that can result in remote code execution. Successful exploitation requires the attacker to win a race condition along with additional actions prior to exploitation to prepare the target environment. An unauthenticated actor can send specially crafted IPv6 packets to a Windows node where IPSec is enabled to potentially achieve remote code execution. 

CVE-2026-32201 is an important improper input validation vulnerability in Microsoft Office SharePoint that can allow an unauthorized user to perform spoofing. An attacker that successfully exploits this vulnerability could view some sensitive information and make changes to disclosed information. This vulnerability has already been detected as being exploited in the wild.

The majority of the remaining vulnerabilities are labeled as important with a two moderate and one low vulnerability also being patched.  Talos would like to highlight the several additional  important vulnerabilities that Microsoft has deemed as “more likely” to be exploited.

·      CVE-2026-0390 - UEFI Secure Boot Security Feature Bypass Vulnerability

·      CVE-2026-26151 - Remote Desktop Spoofing Vulnerability

·      CVE-2026-26169 - Windows Kernel Memory Information Disclosure Vulnerability

·      CVE-2026-26173 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

·      CVE-2026-26177 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

·      CVE-2026-26182 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

·      CVE-2026-27906 - Windows Hello Security Feature Bypass Vulnerability

·      CVE-2026-27908 - Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability

·      CVE-2026-27909 - Windows Search Service Elevation of Privilege Vulnerability

·      CVE-2026-27913 - Windows BitLocker Security Feature Bypass Vulnerability

·      CVE-2026-27914 - Microsoft Management Console Elevation of Privilege Vulnerability

·      CVE-2026-27921 - Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability

·      CVE-2026-27922 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

·      CVE-2026-32070 - Windows Common Log File System Driver Elevation of Privilege Vulnerability

·      CVE-2026-32075 - Windows UPnP Device Host Elevation of Privilege Vulnerability

·      CVE-2026-32093 - Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

·      CVE-2026-32152 - Desktop Window Manager Elevation of Privilege Vulnerability

·      CVE-2026-32154 - Desktop Window Manager Elevation of Privilege Vulnerability

·      CVE-2026-32155 - Desktop Window Manager Elevation of Privilege Vulnerability

·      CVE-2026-32162 - Windows COM Elevation of Privilege Vulnerability

·      CVE-2026-32202 - Windows Shell Spoofing Vulnerability

·      CVE-2026-32225 - Windows Shell Security Feature Bypass Vulnerability

·      CVE-2026-33825 - Microsoft Defender Elevation of Privilege Vulnerability

A complete list of all other vulnerabilities Microsoft disclosed this month is available on its update page. In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.  

The rules included in this release that protect against the exploitation of many of these vulnerabilities are: 1:65902-1:65903, 1:66242-1:66251, 1:66259-1:66260, 1:66264-1:66267, 1:66275-1:66276 

The following Snort 3 rules are also available: 1:301398, 1:301468-1:3101472, 1:301475, 1:301477-1:301478, 1:301480

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-patch-tuesday-april-2026/