ZeroHour
Krebs on Securitypublished ()ingested

Patch Tuesday, April 2026 Edition

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-32201
Improper Input Validation Spoofing Vulnerability in Microsoft SharePoint Server

Microsoft SharePoint Server contains an improper input validation flaw (CWE-20) that can be triggered by an unauthenticated, network-based attacker submitting crafted input to the server. Successful exploitation allows the attacker to perform spoofing over the network, impersonating a trusted user or source within SharePoint; detailed impact mechanics have not been published and no CVSS score or public proof-of-concept is available. Any organization running on-premises Microsoft SharePoint Server is potentially affected, and the available data does not specify affected version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-14, indicating evidence of active exploitation, and EPSS assigns a 42.8% probability of exploitation within 30 days (99th percentile). Ransomware association is currently unknown.

Do: Apply Microsoft's security updates for SharePoint Server per the vendor advisory as soon as possible, and identify your SharePoint Server versions and builds since specific affected ranges are not provided here. Given the KEV listing, federal agencies must apply the vendor mitigations, follow applicable BOD 22-01 cloud guidance, or discontinue use by the established deadline. Until patched, limit network exposure of SharePoint servers and review authentication and access logs for signs of impersonation or spoofing activity.

6.543% KEV
  • Microsoft SharePoint Server
masslikely on the order of 100,000+ on-premises SharePoint Server installations, of which tens of thousands are directly internet-exposed
CVE-2026-33825
Local Privilege Escalation in Microsoft Defender Antimalware Platform

CVE-2026-33825 is an insufficient granularity of access control flaw (CWE-1220) in Microsoft Defender Antimalware Platform that allows an authorized attacker to elevate privileges locally. It is triggered by an attacker who already holds a low-privileged foothold on a machine running Defender, with no user interaction required. Successful exploitation has high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8), granting elevated local rights that facilitate defense evasion, persistence, or ransomware activity. Any organization running Microsoft Defender on Windows endpoints and servers is potentially affected. The flaw is actively exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-22 with ransomware use confirmed, and is one of three Microsoft Defender zero-days reported as exploited, two of which were still unpatched at the time of reporting.

Do: Apply Microsoft's April 2026 Patch Tuesday updates for the Defender Antimalware Platform (platform/security intelligence updates) per vendor instructions, consistent with CISA BOD 22-01 timelines for KEV entries, and note reports that two of the three exploited Defender zero-days were still unpatched, so monitor for follow-up fixes. Prioritize patching internet-reachable and high-value Windows hosts, and hunt for signs of local privilege escalation and ransomware precursor activity on systems that cannot be updated immediately.

7.87% KEV ransomware
  • Microsoft Defender Antimalware Platform
masshundreds of millions of Windows endpoints and servers (Defender is the default antimalware on Windows)
CVE-2026-34621
Actively Exploited Prototype Pollution RCE in Adobe Acrobat and Reader

Adobe Acrobat and Acrobat Reader are affected by a prototype pollution vulnerability (CWE-1321) in which improperly controlled modification of object prototype attributes can lead to arbitrary code execution in the context of the current user. Attackers trigger the flaw by convincing a victim to open a malicious file, typically a crafted PDF, so user interaction is required. Successful exploitation yields code execution as the victim, with the CVSS scope-changed metric indicating impact that extends beyond the vulnerable component. Anyone running Acrobat or Reader versions 24.001.30356 or earlier or 26.001.21367 or earlier is affected. The flaw is being actively exploited in the wild — reportedly via malicious PDFs since December 2025 as a zero-day — and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 after fixes shipped in Adobe's April 2026 Patch Tuesday release; EPSS assigns a 7.1% probability of exploitation within 30 days (94th percentile).

Do: Upgrade Acrobat and Reader to a version later than 24.001.30356 (24.001 series) or 26.001.21367 (26.001 series) via Adobe's April 2026 security update, and audit installed versions across all endpoints. As a CISA KEV entry, US federal agencies must apply the vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable. Until patched, treat PDFs from untrusted sources with caution and monitor for suspicious child-process activity spawned by Acrobat/Reader when files are opened.

8.67% KEV
  • Adobe Acrobat Reader (Acrobat Reader DC) 24.001.30356 and earlier; 26.001.21367 and earlier
  • Adobe Acrobat (Acrobat DC) 24.001.30356 and earlier; 26.001.21367 and earlier
masshundreds of millions of Acrobat/Reader installations worldwide, with likely millions still unpatched
CVE-2026-5281
Use-After-Free in Google Chrome's Dawn (WebGPU) Component Enables Arbitrary Code Execution

CVE-2026-5281 is a use-after-free vulnerability in Dawn, the WebGPU implementation in Google Chrome, that Google patched in Chrome 146.0.7680.178. It is triggered when a remote attacker serves a crafted HTML page and can leverage it after having already compromised the Chrome renderer process, escalating to arbitrary code execution beyond the initial foothold. Because the flaw requires a compromised renderer as a starting point, it is typically chained with another bug (such as a renderer-exploiting issue) to break out to arbitrary code execution with real impact on confidentiality, integrity, and availability. Any user or organization running Google Chrome on a version prior to 146.0.7680.178 is affected. The flaw is confirmed as exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-01, and its EPSS score of 4.9% (92nd percentile) indicates a meaningful near-term exploitation probability.

Do: Update Google Chrome to 146.0.7680.178 or later on all endpoints immediately, prioritizing internet-facing and high-risk user populations given the KEV listing. Because the bug requires a compromised renderer, treat it as part of a chained attack and ensure other browser-layer defenses (renderer sandbox enabled, prompt patching of related renderer bugs) are in place; federal agencies must follow BOD 22-01 remediation timelines or discontinue use if patching is unavailable.

8.85% KEV
  • Google Chrome prior to 146.0.7680.178
  • Google Dawn (WebGPU implementation bundled in Chrome) as shipped in Chrome prior to 146.0.7680.178
masseffectively all Chrome users on unpatched builds
Full article537 words · extracted from krebsonsecurity.com · click to collapse

Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed “BlueHammer.” Separately, Google Chrome fixed its fourth zero-day of 2026, and an emergency update for Adobe Reader nixes an actively exploited flaw that can lead to remote code execution.

A picture of a windows laptop in its updating stage, saying do not turn off the computer.

Redmond warns that attackers are already targeting CVE-2026-32201, a vulnerability in Microsoft SharePoint Server that allows attackers to spoof trusted content or interfaces over a network.

Mike Walters, president and co-founder of Action1, said CVE-2026-32201 can be used to deceive employees, partners, or customers by presenting falsified information within trusted SharePoint environments.

“This CVE can enable phishing attacks, unauthorized data manipulation, or social engineering campaigns that lead to further compromise,” Walters said. “The presence of active exploitation significantly increases organizational risk.”

Microsoft also addressed BlueHammer (CVE-2026-33825), a privilege escalation bug in Windows Defender. According to BleepingComputer, the researcher who discovered the flaw published exploit code for it after notifying Microsoft and growing exasperated with their response. Will Dormann, senior principal vulnerability analyst at Tharros, says he confirmed that the public BlueHammer exploit code no longer works after installing today’s patches.

Satnam Narang, senior staff research engineer at Tenable, said April marks the second-biggest Patch Tuesday ever for Microsoft. Narang also said there are indications that a zero-day flaw Adobe patched in an emergency update on April 11 — CVE-2026-34621 — has seen active exploitation since at least November 2025.

Adam Barnett, lead software engineer at Rapid7, called the patch total from Microsoft today “a new record in that category” because it includes nearly 60 browser vulnerabilities. Barnett said it might be tempting to imagine that this sudden spike was tied to the buzz around the announcement a week ago today of Project Glasswing — a much-hyped but still unreleased new AI capability from Anthropic that is reportedly quite good at finding bugs in a vast array of software.

But he notes that Microsoft Edge is based on the Chromium engine, and the Chromium maintainers acknowledge a wide range of researchers for the vulnerabilities which Microsoft republished last Friday.

“A safe conclusion is that this increase in volume is driven by ever-expanding AI capabilities,” Barnett said. “We should expect to see further increases in vulnerability reporting volume as the impact of AI models extend further, both in terms of capability and availability.”

Finally, no matter what browser you use to surf the web, it’s important to completely close out and restart the browser periodically. This is really easy to put off (especially if you have a bajillion tabs open at any time) but it’s the only way to ensure that any available updates get installed. For example, a Google Chrome update released earlier this month fixed 21 security holes, including the high-severity zero-day flaw CVE-2026-5281.

For a clickable, per-patch breakdown, check out the SANS Internet Storm Center Patch Tuesday roundup. Running into problems applying any of these updates? Leave a note about it in the comments below and there’s a decent chance someone here will pipe in with a solution.

Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2026/04/patch-tuesday-april-2026-edition/