[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fo171Eu8nEuTv2VYW0jEgkHPmwbQAbejfueeEL_cffZ8":3},{"article":4,"iocs":44,"watch_terms":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"72ba5b77-60be-4233-a099-c067d358d71d","Microsoft and Adobe Patch Tuesday, April 2026 Security Update Review","microsoft-and-adobe-patch-tuesday-april-2026-security-update-review-b45453","April 2026’s Patch Tuesday arrives with Microsoft addressing a fresh set of vulnerabilities across its ecosystem, reinforcing the ongoing need for timely patching in an increasingly threat-heavy landscape. Here’s a quick breakdown of what you need to know. Microsoft Patch Tuesday for April 2026 This month’s release addresses 163 vulnerabilities, including eight critical and 154 important-severity vulnerabilities. In this month’s updates, Microsoft has addressed one publicly disclosed zero-day vulnerability and one being exploited in the wild. Microsoft addressed 80 vulnerabilities in Microsoft Edge (Chromium-based) that were patched earlier this month. Microsoft Patch Tuesday, April edition, includes updates for […]","Microsoft's April 2026 Patch Tuesday addresses 163 vulnerabilities (8 critical, 154 important), including one publicly disclosed and one actively exploited zero-day. Adobe releases 12 advisories covering 56 vulnerabilities across its product suite, with 38 rated critical. Critical patches include CVE-2026-33825 (Microsoft Defender elevation of privilege) and CVE-2026-32201 (SharePoint Server spoofing), both with active exploitation confirmed by CISA.","Microsoft and Adobe release April 2026 security patches addressing 163 and 56 vulnerabilities respectively, including","Table of ContentsMicrosoft Patch Tuesday forApril2026Adobe Patches for April2026Zero-day Vulnerabilities Patched inAprilPatch Tuesday EditionCritical Severity Vulnerabilities Patched inAprilPatch Tuesday EditionOther Microsoft Vulnerability HighlightsMicrosoft Release SummaryDiscover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)Rapid Response with TruRisk EliminateEVALUATE Vendor-Suggested Mitigation withPolicy Audit(PA)Qualys Monthly Webinar Series April 2026’s Patch Tuesday arrives with Microsoft addressing a fresh set of vulnerabilities across its ecosystem, reinforcing the ongoing need for timely patching in an increasingly threat-heavy landscape. Here’s a quick breakdown of what you need to know. Microsoft Patch Tuesday for April 2026 This month’s release addresses 163 vulnerabilities, including eight critical-severity vulnerabilities. In this month’s updates, Microsoft has addressed one publicly disclosed zero-day vulnerability and one being exploited in the wild. Microsoft addressed 80 vulnerabilities in Microsoft Edge (Chromium-based) that were patched earlier this month. Microsoft Patch Tuesday, April edition, includes updates for vulnerabilities in Microsoft Graphics Component, Windows Kerberos, Windows Kernel, Windows Hyper-V, Microsoft Windows Speech, Remote Desktop Client, SQL Server, Azure Monitor Agent, Windows BitLocker, Microsoft Management Console, Windows IKE Extension, Microsoft Defender, Input-Output Memory Management Unit (IOMMU), and more. This month’s release includes fixes for several high-severity issues that could potentially enable remote code execution, privilege escalation, or denial-of-service attacks. As always, timely patch deployment is crucial to reduce exposure and ensure systems remain resilient against exploitation attempts. The April 2026 Microsoft vulnerabilities are classified as follows: Vulnerability CategoryQuantitySeveritiesSpoofing Vulnerability8Important: 8Denial of Service Vulnerability9Critical: 1Important: 8Elevation of Privilege Vulnerability93Important: 93Information Disclosure Vulnerability20Important: 20Remote Code Execution Vulnerability20Critical: 7Important: 13Security Feature Bypass Vulnerability12Important: 12 Adobe Patches for April 2026 Adobe has released 12 security advisories to address 56 vulnerabilities in Adobe Acrobat Reader, Adobe Illustrator, Adobe DNG SDK, Adobe Photoshop, Adobe Bridge, Adobe ColdFusion, Adobe Connect, Adobe FrameMaker, Adobe Experience Manager Screens, Adobe InCopy, Adobe InDesign, and Adobe Acrobat Reader. 38 of these vulnerabilities are rated critical. Successful exploitation of these vulnerabilities may lead to privilege escalation, Security feature bypass, arbitrary file system read, and arbitrary code execution. Zero-day Vulnerabilities Patched in April Patch Tuesday Edition CVE-2026-33825: Microsoft Defender Elevation of Privilege Vulnerability Microsoft Defender is a comprehensive, AI-powered security suite that provides malware protection, phishing detection, and web protection for individuals and businesses. An insufficient access-control granularity flaw in Windows Defender could allow an authenticated attacker to elevate local privileges. Insufficient Granularity of Access Control occurs when security policies are too broad, allowing authorized users to access data or perform actions beyond their intended permissions. CISA acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users to patch the vulnerability before May 6, 2026. CVE-2026-32201: Microsoft SharePoint Server Spoofing Vulnerability An improper input validation vulnerability in Microsoft Office SharePoint may allow an unauthenticated attacker to perform network spoofing. CISA acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users to patch the vulnerability before April 28, 2026. Critical Severity Vulnerabilities Patched in April Patch Tuesday Edition CVE-2026-32157: Remote Desktop Client Remote Code Execution Vulnerability A use-after-free flaw in the Remote Desktop Client may allow an unauthenticated attacker to execute code over the network. Successful exploitation of the vulnerability requires an authenticated user on the client to connect to a malicious server. CVE-2026-33826: Windows Active Directory Remote Code Execution Vulnerability An improper input validation flaw in Windows Active Directory could allow an authenticated attacker to execute code on an adjacent network. An attacker must send a specially crafted RPC call to an RPC host to exploit the vulnerability. CVE-2026-23666: .NET Framework Denial of Service Vulnerability A race condition flaw in the .NET Framework could allow an unauthenticated attacker to deny service to network clients. CVE-2026-32190: Microsoft Office Remote Code Execution Vulnerability A use-after-free vulnerability in Microsoft Office may allow an unauthenticated attacker to execute code locally. CVE-2026-33114: Microsoft Word Remote Code Execution Vulnerability A pointer dereference vulnerability in Microsoft Word allows an unauthenticated attacker to execute code locally. CVE-2026-33115: Microsoft Word Remote Code Execution Vulnerability A use-after-free vulnerability in Microsoft Office Word could allow an unauthenticated attacker to execute code locally. CVE-2026-33827: Windows TCP\u002FIP Remote Code Execution Vulnerability A race condition flaw in Windows TCP\u002FIP may allow an unauthenticated attacker to execute code over a network. An attacker could send a specially crafted IPv6 packet to a Windows node with IPSec enabled, leading to remote code execution. CVE-2026-33824: Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange is a foundational network security protocol used by Windows to set up secure, encrypted IPsec tunnels, primarily for VPN connections. An unauthenticated attacker could send specially crafted packets to a Windows machine with Internet Key Exchange version 2 enabled, potentially leading to remote code execution. Other Microsoft Vulnerability Highlights CVE-2026-26151 is a spoofing vulnerability in Remote Desktop. Successful exploitation of the vulnerability allows an unauthenticated attacker to perform network spoofing. CVE-2026-27906 is a security feature bypass vulnerability in Windows Hello. Successful exploitation of the vulnerability may allow an authenticated attacker to bypass a local security feature. CVE-2026-27908 is an elevation-of-privilege vulnerability in the Windows TDI Translation Driver (tdx.sys). A use-after-free flaw may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-27921 is an elevation-of-privilege vulnerability in the Windows TDI Translation Driver (tdx.sys). An attacker may exploit the vulnerability to gain SYSTEM privileges. CVE-2026-32093 is an elevation-of-privilege vulnerability in the Windows Function Discovery Service (fdwsd.dll). An authenticated attacker who successfully exploited this vulnerability could gain administrator privileges. CVE-2026-32152 and CVE-2026-32154 are elevation-of-privilege vulnerabilities in the DesktopWindow Manager. A use-after-free flaw may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-0390 is a security feature bypass vulnerability in the Windows Boot Loader. Successful exploitation of the vulnerability may allow an authenticated attacker to bypass a local security feature. CVE-2026-32202 is a spoofing vulnerability in the Windows Shell. An unauthenticated attacker may exploit the vulnerability to perform network spoofing. CVE-2026-26169 is an information disclosure vulnerability in Windows Kernel Memory. An authenticated attacker may exploit the vulnerability to disclose information locally. CVE-2026-26173 is an elevation-of-privilege vulnerability in the Windows Ancillary Fun","https:\u002F\u002Fblog.qualys.com\u002Fvulnerabilities-threat-research\u002F2026\u002F04\u002F14\u002Fmicrosoft-and-adobe-patch-tuesday-april-2026-security-update-review","https:\u002F\u002Fik.imagekit.io\u002Fqualys\u002Fwp-content\u002Fuploads\u002F2026\u002F04\u002FMicrosoft-Patch-Tuesday-Apr-2026-1.jpg","2026-04-14T20:16:14+00:00","2026-04-14T22:00:12.777723+00:00",9,[18,21,23,26,28,30],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":20},"Adobe",{"name":24,"type":25},"Microsoft Defender","product",{"name":27,"type":25},"Microsoft SharePoint Server",{"name":29,"type":25},"Microsoft Edge",{"name":31,"type":32},"Windows Kerberos","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",[45,49],{"type":46,"value":47,"context":48},"cve","CVE-2026-33825","Microsoft Defender elevation of privilege vulnerability actively exploited in the wild",{"type":46,"value":50,"context":51},"CVE-2026-32201","Microsoft SharePoint Server spoofing vulnerability actively exploited in the wild",[19,22,24]]