Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft April 2026 Patch Tuesday security update (165 CVEs)

Security Patch Release
First reported
Last updated
Happening score
H score 62
2 unique sources, 2 articles

Summary

Hide ▲

Microsoft shipped April 2026 Patch Tuesday updates covering 165 CVEs, including an actively exploited zero-day and a publicly disclosed flaw, creating immediate remediation pressure across Windows and related products. The bundle matters because multiple patched bugs can enable remote code execution, elevation of privilege, or information disclosure. Microsoft also said 19 vulnerabilities are more likely to be exploited and need high-priority attention. The update spans SharePoint Server, Defender, Windows IKE, Word, and nearly 80 Edge/Chromium fixes.

Cases

Related Happenings

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score78 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

Microsoft security patch release for CVE-2026-56164

Security Patch Release
H score11 First: 14.07.2026 23:25 Last: 14.07.2026 23:25 Sources 1

About this happening: Microsoft released a record 622-CVE Patch Tuesday that includes two exploited flaws in SharePoint Server and Active Directory Federation Services, raising urgency...

Microsoft Corp. security patch release for CVE-2026-56155

Security Patch Release
H score48 First: 14.07.2026 22:22 Last: 14.07.2026 22:22 Sources 1

About this happening: Microsoft released July 2026 Patch Tuesday updates that close at least 570 security holes in Windows and other software, expanding the remediation burden for defen...

Microsoft July 2026 Patch Tuesday security updates (570 flaws, 3 zero-days)

Security Patch Release
H score36 First: 14.07.2026 21:01 Last: 14.07.2026 21:01 Sources 1

About this happening: Microsoft's July 2026 Patch Tuesday released security updates for 570 flaws, including three zero-days and two vulnerabilities exploited in attacks, creating immed...

Amazon security patch release for CVE-2026-50549

Security Patch Release
H score29 First: 09.07.2026 14:00 Last: 09.07.2026 14:00 Sources 1

About this happening: Amazon, Google and Cursor shipped fixes for GhostApproval, a flaw in AI coding assistants that let deceptive repository paths bypass approval prompts. The patch response c...

Timeline

  1. 15.04.2026 00:22 1 articles · 3mo ago

    Microsoft April 2026 Patch Tuesday release

    Mitigation Patch Update

    Microsoft's April 2026 Patch Tuesday delivered patches for 165 CVEs, including CVE-2026-32201, an actively exploited spoofing flaw in Microsoft SharePoint Server that can let attackers view and modify sensitive information, and CVE-2026-33825, a publicly disclosed Defender antimalware platform flaw with proof-of-concept code. The update also covered critical fixes for CVE-2026-33824 in Windows Internet Key Exchange (IKE) Service Extensions, CVE-2026-33827 in Windows secure tunneling and authentication components, and nearly 80 republished Microsoft Edge and Chromium patches.

    Show sources
  2. 15.04.2026 00:22 2 articles · 3mo ago

    Microsoft flags exploitation risk and hardening steps

    Technical Analysis Update

    Microsoft assessed 19 newly disclosed vulnerabilities as more likely to be exploited, and researchers warned that CVE-2026-33825 could be chained with other exploits to expand initial access and gain system-level control on vulnerable endpoints. Microsoft said Defender instances with automatic updates were already protected, while organizations that do not use IKE should block UDP ports 500 and 4500 and required IKE deployments should restrict inbound traffic to known peer addresses.

    Show sources