Skip to content
Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero

Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero

Bleepingcomputer Lawrence Abrams April 14, 2026

Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.

This Patch Tuesday also addresses eight "Critical" vulnerabilities, 7 of which are remote code execution flaws and the other is a denial of service flaw.

The number of bugs in each vulnerability category is listed below:

When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today.

Therefore, the number of flaws does not include Mariner, Azure, and Bing flaws that were fixed by Microsoft earlier this month. There were also 80 Microsoft Edge/Chromium flaws that were fixed by Google.

This month's Patch Tuesday fixes two zero-day vulnerabilities, with one publicly disclosed and the other actively exploited in attacks.

Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.

The actively exploited zero-day flaw is:

CVE-2026-32201 - Microsoft SharePoint Server Spoofing Vulnerability

Microsoft has patched a Microsoft SharePoint Server Spoofing Vulnerability that was exploited in attacks.

"Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network," explains Microsoft.

"An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality), make changes to disclosed information (Integrity), but cannot limit access to the resource (Availability)," continued Microsoft.

Microsoft has not disclosed how this vulnerability was exploited in attacks or who disclosed it.

The publicly disclosed zero-day is:

CVE-2026-33825 - Microsoft Defender Elevation of Privilege Vulnerability

Microsoft has patched a Microsoft Defender privilege elevation flaw that gives SYSTEM privileges.

The company has addressed the flaw in the Microsoft Defender Antimalware Platform update version 4.18.26050.3011 , which will automatically be downloaded to systems.

Windows users can manually install it by going to Windows Security > Virus & threat protection > Protection Updates , then clicking Check for updates .

Microsoft has credited Zen Dodd and Yuanpei XU (HUST) with Diffract with discovering this flaw.

Microsoft has also fixed multiple remote code execution bugs in Microsoft Office (Word and Excel) that can be executed via the preview pane or by opening malicious documents.

Therefore, users should prioritize updating Microsoft Office as soon as possible, especially if they commonly receive attachments.

Other vendors who released updates or advisories in April 2026 include:

Below is the complete list of resolved vulnerabilities in the April 2026 Patch Tuesday updates.

To access the full description of each vulnerability and the systems it affects, you can view the full report here .

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.