news.mlab.sh
Back to the feed
threat-intel

Patch Tuesday, April 2026 Edition

High
Summary

Microsoft released a substantial update, Patch Tuesday, addressing 167 vulnerabilities across its operating systems and software, including several zero-days. This update focused on critical flaws in SharePoint Server, Windows Defender, and Adobe Reader, with evidence suggesting ongoing exploitation of a previously disclosed Adobe vulnerability. The sheer volume of patches highlights the ongoing challenge of securing complex software ecosystems.

Microsoft’s Patch Tuesday release included fixes for a significant number of vulnerabilities, primarily targeting its core products. The most pressing issue was CVE-2026-32201, a zero-day vulnerability in SharePoint Server, which allows attackers to impersonate trusted content and potentially initiate phishing attacks or data manipulation campaigns. This vulnerability’s active exploitation underscores the urgency of patching. Furthermore, a privilege escalation bug, dubbed BlueHammer (CVE-2026-33825), was found in Windows Defender, and the availability of exploit code raised concerns about rapid attacks. Alongside these, a previously patched Adobe Reader vulnerability (CVE-2026-34621) was confirmed to have been actively exploited since November 2025, highlighting the difficulty of keeping software secure even after initial patching. The large number of browser vulnerabilities, particularly within Microsoft Edge, suggests a broader trend driven by expanding AI capabilities.

Read the full article at Krebs on Security