Microsoft March and April 2026 Patch Tuesdays Address Multiple Zero-Days and Critical Flaws
Summary
Hide ▲
Show ▼
Microsoft’s multi-month Patch Tuesday campaign continues with the April 2026 release addressing 167 security vulnerabilities in Windows and related software, including two actively exploited zero-days (CVE-2026-32201 in SharePoint Server and CVE-2026-33825 in Microsoft Defender). Nearly 60% of the patched flaws are elevation-of-privilege bugs, marking the highest proportion in eight months, while eight Critical vulnerabilities were addressed, including unauthenticated remote code execution flaws in Windows IKE Service Extensions (CVE-2026-33824, CVSS 9.8) and secure tunneling components (CVE-2026-33827, CVSS 8.1). Following the April updates, threat actors are now exploiting two additional unpatched Microsoft Defender zero-days—RedSun and UnDefend—alongside the patched CVE-2026-33825 (BlueHammer). Exploitation activity has been observed since April 10, 2026, with RedSun and UnDefend PoCs deployed on April 16, 2026, featuring hands-on-keyboard techniques such as whoami /priv, cmdkey /list, and net group commands. Huntress confirmed real-world exploitation and took steps to isolate compromised systems to prevent post-exploitation damage. Threat actors have also been observed chaining these flaws with other vulnerabilities to achieve full endpoint control. Microsoft issued out-of-band emergency patches for CVE-2026-40372, a critical ASP.NET Core privilege escalation vulnerability in the ASP.NET Core Data Protection cryptographic APIs. The flaw enables unauthenticated attackers to gain SYSTEM privileges by forging authentication cookies, stemming from a regression in Microsoft.AspNetCore.DataProtection 10.0.0-10.0.6 packages. Microsoft recommends updating to version 10.0.7 and rotating the DataProtection key ring to fully remediate. The April updates were distributed through Windows 11 cumulative updates KB5083769 (for versions 25H2/24H2) and KB5082052 (for 23H2), changing build numbers to 26200.8246 (25H2), 26100.8246 (24H2), and 22631.6936 (23H2). Windows 10 Enterprise LTSC and ESU participants received the April fixes via KB5082200, updating to build 19045.7184 (Windows 10) or 19044.7184 (Windows 10 Enterprise LTSC 2021).
Timeline
-
14.04.2026 20:41 7 articles · 8d ago
Microsoft April 2026 Patch Tuesday addresses 167 flaws including two zero-days
Adds newly observed exploitation context for Microsoft Defender zero-days: - Confirms CVE-2026-33825 (BlueHammer) was patched in April 2026 Patch Tuesday but remains a key target; exploitation activity dates to April 10, 2026, with further deployment of RedSun and UnDefend PoCs on April 16, 2026 - Documents hands-on-keyboard threat actor activity (e.g., whoami /priv, cmdkey /list, net group) during exploitation of Microsoft Defender flaws - Huntress observed exploitation of BlueHammer, RedSun, and UnDefend in compromised environments and took action to isolate affected organizations to prevent post-exploitation damage
Show sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
- Windows 11 cumulative updates KB5083769 & KB5082052 released — www.bleepingcomputer.com — 14.04.2026 20:46
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
10.03.2026 19:49 6 articles · 1mo ago
Microsoft March 2026 Patch Tuesday Addresses 2 Zero-Days and 79 Flaws
Microsoft's March 2026 Patch Tuesday addresses 84 vulnerabilities, including 2 publicly disclosed zero-day flaws. The updates fix critical vulnerabilities, including remote code execution flaws and information disclosure flaws. The patches cover a range of vulnerabilities, including elevation of privilege, security feature bypass, remote code execution, information disclosure, denial of service, and spoofing. Notably, CVE-2026-21262 allows attackers to elevate privileges to sysadmin over a network on SQL Server 2016 and later editions. Additionally, Microsoft fixed two remote code execution bugs in Microsoft Office that can be exploited via the preview pane. A notable flaw in Microsoft Excel could allow data exfiltration via Microsoft Copilot. The updates also include patches for nine browser vulnerabilities and an out-of-band update for Windows Server 2022 to address a certificate renewal issue with Windows Hello for Business. Microsoft is changing the default behavior of Windows Autopatch to enable hotpatch security updates starting with the May 2026 Windows security update. This timeline phase is updated to reflect the corrected total of 84 vulnerabilities addressed, as confirmed by subsequent reporting.
Show sources
- Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws — www.bleepingcomputer.com — 10.03.2026 19:49
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
Information Snippets
-
Microsoft released security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
First reported: 10.03.2026 19:495 sources, 5 articlesShow sources
- Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws — www.bleepingcomputer.com — 10.03.2026 19:49
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
The updates address 3 critical vulnerabilities, 2 of which are remote code execution flaws and 1 is an information disclosure flaw.
First reported: 10.03.2026 19:495 sources, 5 articlesShow sources
- Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws — www.bleepingcomputer.com — 10.03.2026 19:49
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
The vulnerabilities include 46 elevation of privilege, 2 security feature bypass, 18 remote code execution, 10 information disclosure, 4 denial of service, and 4 spoofing flaws.
First reported: 10.03.2026 19:495 sources, 5 articlesShow sources
- Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws — www.bleepingcomputer.com — 10.03.2026 19:49
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-21262 is a SQL Server elevation of privilege vulnerability that allows unauthorized attackers to elevate privileges over a network.
First reported: 10.03.2026 19:495 sources, 5 articlesShow sources
- Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws — www.bleepingcomputer.com — 10.03.2026 19:49
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-26127 is a .NET denial of service flaw that allows unauthorized attackers to deny service over a network.
First reported: 10.03.2026 19:495 sources, 5 articlesShow sources
- Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws — www.bleepingcomputer.com — 10.03.2026 19:49
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-26110 and CVE-2026-26113 are remote code execution bugs in Microsoft Office that can be exploited via the preview pane.
First reported: 10.03.2026 19:495 sources, 5 articlesShow sources
- Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws — www.bleepingcomputer.com — 10.03.2026 19:49
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-26144 is an Excel information disclosure flaw that could allow data exfiltration via Microsoft Copilot.
First reported: 10.03.2026 19:495 sources, 5 articlesShow sources
- Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws — www.bleepingcomputer.com — 10.03.2026 19:49
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-21262 allows an attacker to elevate privileges to sysadmin over a network on SQL Server 2016 and later editions.
First reported: 11.03.2026 02:324 sources, 4 articlesShow sources
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-26127 is a .NET vulnerability that can cause denial of service by triggering a crash.
First reported: 11.03.2026 02:324 sources, 4 articlesShow sources
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-24291 is an incorrect permission assignment within the Windows Accessibility Infrastructure.
First reported: 11.03.2026 02:324 sources, 4 articlesShow sources
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-24294 is an improper authentication flaw in the core SMB component.
First reported: 11.03.2026 02:324 sources, 4 articlesShow sources
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-24289 is a high-severity memory corruption and race condition flaw.
First reported: 11.03.2026 02:324 sources, 4 articlesShow sources
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-25187 is a Winlogon process weakness discovered by Google Project Zero.
First reported: 11.03.2026 02:324 sources, 4 articlesShow sources
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-21536 is a critical remote code execution bug in the Microsoft Devices Pricing Program, discovered by an AI agent.
First reported: 11.03.2026 02:324 sources, 4 articlesShow sources
- Microsoft Patch Tuesday, March 2026 Edition — krebsonsecurity.com — 11.03.2026 02:32
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
Microsoft released patches for 83 CVEs in the March 2026 update.
First reported: 11.03.2026 03:083 sources, 3 articlesShow sources
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
Six vulnerabilities are considered more likely to be exploited by attackers.
First reported: 11.03.2026 03:083 sources, 3 articlesShow sources
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2027-21536 is a critical RCE vulnerability in the Microsoft Devices Pricing Program with a CVSS score of 9.8.
First reported: 11.03.2026 03:083 sources, 3 articlesShow sources
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
Elevation of privilege (EoP) bugs accounted for 55.4% of the patched CVEs.
First reported: 11.03.2026 03:083 sources, 3 articlesShow sources
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-24289 and CVE-2026-26132 are EoP vulnerabilities in the Windows kernel with low attack complexity.
First reported: 11.03.2026 03:083 sources, 3 articlesShow sources
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-24294 is an EoP vulnerability in SMB Server, and CVE-2026-23668 is an EoP vulnerability in Microsoft Graphics Component.
First reported: 11.03.2026 03:083 sources, 3 articlesShow sources
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-26113 and CVE-2026-26110 are RCE vulnerabilities in Microsoft Office that can be exploited via the preview pane.
First reported: 11.03.2026 03:083 sources, 3 articlesShow sources
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-25190 and CVE-2026-25181 are vulnerabilities in GDI and GDI+ that can be chained for a dual-stage attack.
First reported: 11.03.2026 03:083 sources, 3 articlesShow sources
- Microsoft Patches 83 CVEs in March Update — www.darkreading.com — 11.03.2026 03:08
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
Microsoft released patches for 84 CVEs in the March 2026 update.
First reported: 11.03.2026 11:152 sources, 2 articlesShow sources
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
Eight vulnerabilities are rated Critical, and 76 are rated Important in severity.
First reported: 11.03.2026 11:153 sources, 3 articlesShow sources
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
CVE-2026-26127 is a denial-of-service vulnerability in .NET with a CVSS score of 7.5.
First reported: 11.03.2026 11:152 sources, 2 articlesShow sources
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-21262 is an elevation of privilege vulnerability in SQL Server with a CVSS score of 8.8.
First reported: 11.03.2026 11:152 sources, 2 articlesShow sources
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-21536 is a critical remote code execution flaw in the Microsoft Devices Pricing Program with a CVSS score of 9.8.
First reported: 11.03.2026 11:152 sources, 2 articlesShow sources
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-25187 is a Winlogon privilege escalation flaw with a CVSS score of 7.8.
First reported: 11.03.2026 11:152 sources, 2 articlesShow sources
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-26118 is a server-side request forgery bug in the Azure Model Context Protocol (MCP) server with a CVSS score of 8.8.
First reported: 11.03.2026 11:152 sources, 2 articlesShow sources
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-26144 is an information disclosure flaw in Excel with a CVSS score of 7.5.
First reported: 11.03.2026 11:152 sources, 2 articlesShow sources
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
Microsoft is changing the default behavior of Windows Autopatch to enable hotpatch security updates starting with the May 2026 Windows security update.
First reported: 11.03.2026 11:152 sources, 2 articlesShow sources
- Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days — thehackernews.com — 11.03.2026 11:15
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-21262 is an SQL Server elevation of privilege (EoP) bug with a CVSS score of 8.8.
First reported: 11.03.2026 11:201 source, 1 articleShow sources
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
CVE-2026-26127 is a denial-of-service flaw in .NET that could have serious exploitation implications.
First reported: 11.03.2026 11:201 source, 1 articleShow sources
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
Microsoft released security updates for 79 vulnerabilities in this month's Patch Tuesday.
First reported: 11.03.2026 11:201 source, 1 articleShow sources
- Microsoft Fixes Two Publicly Disclosed Zero-Days — www.infosecurity-magazine.com — 11.03.2026 11:20
-
Microsoft's April 2026 Patch Tuesday addresses 167 vulnerabilities, including 2 zero-day flaws.
First reported: 14.04.2026 20:413 sources, 3 articlesShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
-
Eight of the patched vulnerabilities are classified as Critical, including 7 remote code execution flaws and 1 denial of service flaw.
First reported: 14.04.2026 20:412 sources, 2 articlesShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
The breakdown of patched vulnerabilities includes 93 elevation of privilege, 13 security feature bypass, 20 remote code execution, 21 information disclosure, 10 denial of service, and 9 spoofing vulnerabilities.
First reported: 14.04.2026 20:412 sources, 2 articlesShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
CVE-2026-32201 is an actively exploited Microsoft SharePoint Server spoofing vulnerability that allows unauthorized attackers to perform spoofing over a network.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
CVE-2026-33825 is a publicly disclosed Microsoft Defender elevation of privilege vulnerability that grants SYSTEM privileges and is addressed in Microsoft Defender Antimalware Platform update version 4.18.26050.3011.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
Adobe released security updates for multiple products, including a fix for an actively exploited zero-day in Reader/Acrobat.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
Apache patched a 13-year-old remote code execution vulnerability in Apache ActiveMQ Classic.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
Apple expanded security updates to more iPhones running iOS 18 to protect against the actively exploited DarkSword exploit kit.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
Cisco released security updates addressing an authentication bypass in Integrated Management Controller (IMC) granting Admin access.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
Fortinet addressed a critical, actively exploited vulnerability, CVE-2026-35616, in FortiClient Enterprise Management Server (EMS).
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
Google fixed a zero-day vulnerability in Google Chrome that was exploited in attacks.
First reported: 14.04.2026 20:412 sources, 2 articlesShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
A new GPUBreach rowhammer attack can escalate privileges and lead to full system compromise.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
Marimo released a security update for a pre-authentication remote code execution flaw now being exploited in attacks.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
SAP addressed a critical SQL injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
The wolfSSL SSL/TLS library released a security update to prevent acceptance of forged certificates.
First reported: 14.04.2026 20:411 source, 1 articleShow sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
-
CVE-2026-32201 is an actively exploited Microsoft SharePoint Server spoofing vulnerability addressed in the April 2026 Patch Tuesday updates
First reported: 14.04.2026 20:462 sources, 2 articlesShow sources
- Windows 11 cumulative updates KB5083769 & KB5082052 released — www.bleepingcomputer.com — 14.04.2026 20:46
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
CVE-2026-33825 is a publicly disclosed Microsoft Defender elevation of privilege flaw granting SYSTEM privileges, addressed in Microsoft Defender Antimalware Platform update version 4.18.26050.3011
First reported: 14.04.2026 20:462 sources, 2 articlesShow sources
- Windows 11 cumulative updates KB5083769 & KB5082052 released — www.bleepingcomputer.com — 14.04.2026 20:46
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
Microsoft released Windows 11 cumulative updates KB5083769 and KB5082052 to address April 2026 Patch Tuesday security vulnerabilities
First reported: 14.04.2026 20:463 sources, 3 articlesShow sources
- Windows 11 cumulative updates KB5083769 & KB5082052 released — www.bleepingcomputer.com — 14.04.2026 20:46
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
KB5083769 targets Windows 11 versions 25H2/24H2 while KB5082052 covers version 23H2
First reported: 14.04.2026 20:463 sources, 3 articlesShow sources
- Windows 11 cumulative updates KB5083769 & KB5082052 released — www.bleepingcomputer.com — 14.04.2026 20:46
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
The April 2026 Patch Tuesday updates change Windows 11 build numbers to 26200.8246 for 25H2, 26100.8246 for 24H2, and 22631.6936 for 23H2
First reported: 14.04.2026 20:463 sources, 3 articlesShow sources
- Windows 11 cumulative updates KB5083769 & KB5082052 released — www.bleepingcomputer.com — 14.04.2026 20:46
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
Smart App Control can now be modified without requiring a fresh Windows 11 installation
First reported: 14.04.2026 20:462 sources, 2 articlesShow sources
- Windows 11 cumulative updates KB5083769 & KB5082052 released — www.bleepingcomputer.com — 14.04.2026 20:46
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
Narrator now provides rich image descriptions on Copilot+ PCs and works with Copilot on all Windows 11 devices
First reported: 14.04.2026 20:463 sources, 3 articlesShow sources
- Windows 11 cumulative updates KB5083769 & KB5082052 released — www.bleepingcomputer.com — 14.04.2026 20:46
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
The System File Checker (sfc /scannow) error reporting issues were patched in the April updates
First reported: 14.04.2026 20:463 sources, 3 articlesShow sources
- Windows 11 cumulative updates KB5083769 & KB5082052 released — www.bleepingcomputer.com — 14.04.2026 20:46
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
Microsoft released the Windows 10 KB5082200 extended security update to address the April 2026 Patch Tuesday vulnerabilities, including two zero-days
First reported: 14.04.2026 21:093 sources, 3 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
KB5082200 introduces Remote Desktop Protocol file phishing protections
First reported: 14.04.2026 21:093 sources, 4 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Microsoft adds Windows protections for malicious Remote Desktop files — www.bleepingcomputer.com — 15.04.2026 01:23
-
KB5082200 adds Windows Security indicators to show the rollout status of new Secure Boot certificates
First reported: 14.04.2026 21:092 sources, 2 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
Windows 10 will be updated to build 19045.7184 after installing KB5082200
First reported: 14.04.2026 21:092 sources, 2 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
Windows 10 Enterprise LTSC 2021 will be updated to build 19044.7184 after installing KB5082200
First reported: 14.04.2026 21:093 sources, 3 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
KB5082200 fixes an issue causing some Intel-based devices to enter BitLocker recovery when restarted due to Connected Standby support
First reported: 14.04.2026 21:093 sources, 3 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
KB5082200 resolves a sign-in issue where Microsoft account authentication fails despite working internet connectivity
First reported: 14.04.2026 21:093 sources, 3 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
KB5082200 enables dynamic status reporting for Secure Boot states in the Windows Security App
First reported: 14.04.2026 21:092 sources, 2 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
KB5082200 addresses a Secure Boot update issue that could trigger BitLocker Recovery mode
First reported: 14.04.2026 21:092 sources, 2 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
KB5082200 introduces high confidence device targeting data for Windows quality updates to improve Secure Boot certificate rollout coverage
First reported: 14.04.2026 21:092 sources, 2 articlesShow sources
- Microsoft releases Windows 10 KB5082200 extended security update — www.bleepingcomputer.com — 14.04.2026 21:09
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
Microsoft assessed 19 of the newly disclosed vulnerabilities as flaws that attackers are more likely to exploit, requiring high-priority attention
First reported: 15.04.2026 00:223 sources, 3 articlesShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
Nearly 60% of the patched flaws in April 2026 are elevation-of-privilege (EoP) bugs, marking the highest proportion in the last eight months
First reported: 15.04.2026 00:223 sources, 3 articlesShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
-
CVE-2026-32201 (CVSS: 6.5) is an actively exploited zero-day spoofing vulnerability in Microsoft SharePoint Server that allows attackers to view and modify sensitive information
First reported: 15.04.2026 00:223 sources, 3 articlesShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
-
CVE-2026-33825 (CVSS: 7.8) is a publicly disclosed, unexploited elevation-of-privilege flaw in Microsoft Defender that grants SYSTEM privileges when exploited
First reported: 15.04.2026 00:224 sources, 4 articlesShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
CVE-2026-33825 is linked to the BlueHammer proof-of-concept exploit recently disclosed by a researcher
First reported: 15.04.2026 00:223 sources, 3 articlesShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
-
CVE-2026-33824 (CVSS: 9.8) is an unauthenticated remote code execution flaw in Windows Internet Key Exchange (IKE) Service Extensions
First reported: 15.04.2026 00:223 sources, 3 articlesShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
-
CVE-2026-33827 (CVSS: 8.1) is an unauthenticated remote code execution vulnerability affecting Windows secure tunneling and authentication components
First reported: 15.04.2026 00:222 sources, 2 articlesShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
CVE-2026-33114 and CVE-2026-33115 (both CVSS: 8.4) are critical remote code execution flaws in Microsoft Word with low exploitation likelihood
First reported: 15.04.2026 00:221 source, 1 articleShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
CVE-2026-26151 (CVSS: 7.1) is a spoofing vulnerability in Windows Desktop rated as more likely to be exploited
First reported: 15.04.2026 00:221 source, 1 articleShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
CVE-2026-26169 (CVSS: 6.1) is an information disclosure flaw affecting Windows Kernel memory
First reported: 15.04.2026 00:221 source, 1 articleShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
CVE-2026-27906 (CVSS: 4.4) is a Windows Hello security bypass vulnerability
First reported: 15.04.2026 00:221 source, 1 articleShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
Microsoft Edge and Chromium received nearly 80 patches as part of the April 2026 security update, with deployment requiring minimal effort and downtime
First reported: 15.04.2026 00:222 sources, 2 articlesShow sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
Microsoft patched CVE-2026-33120, a critical SQL Server remote code execution vulnerability allowing network-based attacks
First reported: 15.04.2026 00:471 source, 1 articleShow sources
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
Researchers noted CVE-2026-32201 enables phishing attacks and unauthorized data manipulation within SharePoint environments
First reported: 15.04.2026 00:472 sources, 2 articlesShow sources
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
-
The April 2026 Patch Tuesday fixes represent the second-biggest Patch Tuesday ever for Microsoft, with nearly 60 browser vulnerabilities included
First reported: 15.04.2026 00:471 source, 1 articleShow sources
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
Google Chrome's April emergency update addressed CVE-2026-5281, a high-severity zero-day flaw exploited in the wild
First reported: 15.04.2026 00:471 source, 1 articleShow sources
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
Adobe Reader's April 11 emergency update fixed CVE-2026-34621, an actively exploited flaw since at least November 2025
First reported: 15.04.2026 00:471 source, 1 articleShow sources
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
The BlueHammer exploit code (CVE-2026-33825) was published after the researcher grew frustrated with Microsoft's response timeline
First reported: 15.04.2026 00:472 sources, 2 articlesShow sources
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
Microsoft Edge vulnerabilities were derived from Chromium maintainers' recent fixes, reflecting broader AI-driven vulnerability discovery trends
First reported: 15.04.2026 00:471 source, 1 articleShow sources
- Patch Tuesday, April 2026 Edition — krebsonsecurity.com — 15.04.2026 00:47
-
CVE-2026-32201 is being actively exploited in the wild to manipulate information presentation in SharePoint environments and enable phishing attacks
First reported: 15.04.2026 12:102 sources, 2 articlesShow sources
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
Exploitation of CVE-2026-32201 does not directly impact data integrity but can deceive users into trusting malicious content within trusted SharePoint environments
First reported: 15.04.2026 12:101 source, 1 articleShow sources
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
-
CVE-2026-33825 could be chained with other vulnerabilities in real-world attacks to gain full control over endpoints, enabling data exfiltration, disabling security tools, and lateral movement
First reported: 15.04.2026 12:102 sources, 2 articlesShow sources
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
CVE-2026-33824 is an unauthenticated remote code execution flaw with CVSS 9.8 in Windows IKE Service Extensions that poses serious threats to enterprise environments using VPN or IPsec
First reported: 15.04.2026 12:101 source, 1 articleShow sources
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
-
Exploitation of CVE-2026-33824 could allow attackers to steal sensitive data, disrupt operations, or move laterally across networks
First reported: 15.04.2026 12:101 source, 1 articleShow sources
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
-
CVE-2026-33825 is publicly disclosed but not currently exploited in the wild
First reported: 15.04.2026 12:102 sources, 2 articlesShow sources
- Microsoft Fixes Two Zero-Days in April Patch Tuesday — www.infosecurity-magazine.com — 15.04.2026 12:10
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
CVE-2026-33825 has two additional related zero-days (BlueHammer and RedSun) actively exploited in the wild, with BlueHammer receiving a CVE and a Microsoft Defender Antimalware Platform update (version 4.18.26050.3011) but RedSun remaining unpatched
First reported: 17.04.2026 16:211 source, 1 articleShow sources
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
The BlueHammer exploit has been weaponized since April 10, 2026, with RedSun and UnDefend PoCs deployed on April 16, 2026
First reported: 17.04.2026 16:211 source, 1 articleShow sources
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
Threat actors use enumeration commands (whoami /priv, cmdkey /list, net group) indicative of hands-on-keyboard activity during exploitation of Microsoft Defender flaws
First reported: 17.04.2026 16:211 source, 1 articleShow sources
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
Huntress observed exploitation of all three disclosed Microsoft Defender flaws (BlueHammer, RedSun, UnDefend) in compromised environments and took action to isolate affected organizations
First reported: 17.04.2026 16:211 source, 1 articleShow sources
- Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched — thehackernews.com — 17.04.2026 16:21
-
Microsoft released out-of-band (OOB) security updates to patch CVE-2026-40372, a critical ASP.NET Core privilege escalation vulnerability in the ASP.NET Core Data Protection cryptographic APIs
First reported: 22.04.2026 11:081 source, 1 articleShow sources
- Microsoft releases emergency patches for critical ASP.NET flaw — www.bleepingcomputer.com — 22.04.2026 11:08
Similar Happenings
LSASS crash triggers reboot loops on Windows domain controllers post-April 2026 updates
Microsoft has confirmed that non-Global Catalog Windows domain controllers running April 2026 security updates (KB5082063) are entering reboot loops due to Local Security Authority Subsystem Service (LSASS) crashes during startup. The issue affects environments using Privileged Access Management (PAM) and disrupts authentication and directory services, potentially rendering domains unavailable. Affected platforms include Windows Server 2025, 2022, 23H2, 2019, and 2016. Microsoft is investigating and recommends contacting Support for Business for mitigation measures.
Microsoft Defender zero-day exploits RedSun, BlueHammer, and UnDefend actively abused in the wild
Microsoft Defender is being actively abused in the wild using three proof-of-concept exploits—RedSun, BlueHammer (CVE-2026-33825), and UnDefend—released by researcher "Nightmare-Eclipse" after alleged poor responses from Microsoft Security Response Center (MSRC). RedSun and BlueHammer enable SYSTEM-level privilege escalation on fully patched Windows 10, 11, and Server 2019+ systems with Defender enabled, while UnDefend degrades Defender’s threat detection capabilities without triggering alerts. Attackers are staging binaries in low-noise directories and manually enumerating privileges before exploitation, reflecting targeted hands-on intrusions. Microsoft patched BlueHammer in April updates but has not addressed RedSun or UnDefend, which operate via separate flaws in Defender’s privileged file handling workflows.
BitLocker recovery prompts triggered on Windows Server 2025 after KB5082063 update
Microsoft has confirmed that the April 2026 KB5082063 security update for Windows Server 2025 is causing two distinct issues: BitLocker recovery prompts on first reboot for systems with PCR7-bound Group Policy configurations, and installation failures marked by 0x800F0983 errors on some devices. Both issues primarily impact enterprise-managed systems and require administrative intervention—either key entry for BitLocker recovery or troubleshooting update installation. Microsoft is investigating both problems and has provided temporary workarounds, including Known Issue Rollback (KIR) for BitLocker recovery and diagnostic reviews for update installation failures. Home users are unlikely to be affected by either issue.
BlueHammer Windows local privilege escalation zero-day exploit leaked
Exploit code for an unpatched Windows privilege escalation vulnerability, tracked as BlueHammer, has been publicly released by a disgruntled security researcher. The flaw enables local attackers to escalate privileges to SYSTEM or elevated administrator levels, allowing full system compromise. Microsoft has not issued a patch, classifying the issue as a zero-day. The exploit combines a TOCTOU (time-of-check to time-of-use) and path confusion, granting access to the Security Account Manager (SAM) database to extract local account password hashes. The leak follows frustration with Microsoft’s Security Response Center (MSRC) over disclosure handling, with the researcher citing insufficient response as the trigger for public disclosure. The PoC code contains reliability issues, particularly on Windows Server platforms.
Google Chrome Zero-Day Exploits in Skia and V8 Engine
Google has released emergency updates for Chrome to patch two actively exploited zero-day vulnerabilities (CVE-2026-3909 and CVE-2026-3910). The first is an out-of-bounds write flaw in Skia, a 2D graphics library, which could lead to browser crashes or code execution. The second is an inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine. Both vulnerabilities were discovered and patched within two days of reporting, affecting Windows, macOS, and Linux systems. The updates are rolling out to users, though it may take days or weeks to reach all users. Google has not disclosed further details about the attacks exploiting these vulnerabilities. Google has patched a total of three actively weaponized Chrome zero-days since the start of the year.