Microsoft April 2026 Patch Tuesday security update (165 CVEs)
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft shipped April 2026 Patch Tuesday updates covering 165 CVEs, including an actively exploited zero-day and a publicly disclosed flaw, creating immediate remediation pressure across Windows and related products. The bundle matters because multiple patched bugs can enable remote code execution, elevation of privilege, or information disclosure. Microsoft also said 19 vulnerabilities are more likely to be exploited and need high-priority attention. The update spans SharePoint Server, Defender, Windows IKE, Word, and nearly 80 Edge/Chromium fixes.
Cases
Related Happenings
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation Wave
H score78
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation WaveAbout this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft security patch release for CVE-2026-56164
Security Patch Release
H score11
First: 14.07.2026 23:25
Last: 14.07.2026 23:25
Sources 1
About this happening:
Microsoft released a record 622-CVE Patch Tuesday that includes two exploited flaws in SharePoint Server and Active Directory Federation Services, raising urgency...
Microsoft security patch release for CVE-2026-56164
Security Patch ReleaseAbout this happening: Microsoft released a record 622-CVE Patch Tuesday that includes two exploited flaws in SharePoint Server and Active Directory Federation Services, raising urgency...
Microsoft Corp. security patch release for CVE-2026-56155
Security Patch Release
H score48
First: 14.07.2026 22:22
Last: 14.07.2026 22:22
Sources 1
About this happening:
Microsoft released July 2026 Patch Tuesday updates that close at least 570 security holes in Windows and other software, expanding the remediation burden for defen...
Microsoft Corp. security patch release for CVE-2026-56155
Security Patch ReleaseAbout this happening: Microsoft released July 2026 Patch Tuesday updates that close at least 570 security holes in Windows and other software, expanding the remediation burden for defen...
Microsoft July 2026 Patch Tuesday security updates (570 flaws, 3 zero-days)
Security Patch Release
H score36
First: 14.07.2026 21:01
Last: 14.07.2026 21:01
Sources 1
About this happening:
Microsoft's July 2026 Patch Tuesday released security updates for 570 flaws, including three zero-days and two vulnerabilities exploited in attacks, creating immed...
Microsoft July 2026 Patch Tuesday security updates (570 flaws, 3 zero-days)
Security Patch ReleaseAbout this happening: Microsoft's July 2026 Patch Tuesday released security updates for 570 flaws, including three zero-days and two vulnerabilities exploited in attacks, creating immed...
Amazon security patch release for CVE-2026-50549
Security Patch Release
H score29
First: 09.07.2026 14:00
Last: 09.07.2026 14:00
Sources 1
About this happening:
Amazon, Google and Cursor shipped fixes for GhostApproval, a flaw in AI coding assistants that let deceptive repository paths bypass approval prompts. The patch response c...
Amazon security patch release for CVE-2026-50549
Security Patch ReleaseAbout this happening: Amazon, Google and Cursor shipped fixes for GhostApproval, a flaw in AI coding assistants that let deceptive repository paths bypass approval prompts. The patch response c...
Timeline
-
15.04.2026 00:22 1 articles · 3mo ago
Microsoft April 2026 Patch Tuesday release
Mitigation Patch UpdateMicrosoft's April 2026 Patch Tuesday delivered patches for 165 CVEs, including CVE-2026-32201, an actively exploited spoofing flaw in Microsoft SharePoint Server that can let attackers view and modify sensitive information, and CVE-2026-33825, a publicly disclosed Defender antimalware platform flaw with proof-of-concept code. The update also covered critical fixes for CVE-2026-33824 in Windows Internet Key Exchange (IKE) Service Extensions, CVE-2026-33827 in Windows secure tunneling and authentication components, and nearly 80 republished Microsoft Edge and Chromium patches.
Show sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
-
15.04.2026 00:22 2 articles · 3mo ago
Microsoft flags exploitation risk and hardening steps
Technical Analysis UpdateMicrosoft assessed 19 newly disclosed vulnerabilities as more likely to be exploited, and researchers warned that CVE-2026-33825 could be chained with other exploits to expand initial access and gain system-level control on vulnerable endpoints. Microsoft said Defender instances with automatic updates were already protected, while organizations that do not use IKE should block UDP ports 500 and 4500 and required IKE deployments should restrict inbound traffic to known peer addresses.
Show sources
- Privilege Elevation Dominates Massive Microsoft Patch Update — www.darkreading.com — 15.04.2026 00:22
- Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday — thehackernews.com — 13.05.2026 16:46