Microsoft Addresses 163 CVEs - April Patch Tuesday Update

Microsoft released 163 patches for April Patch Tuesday, addressing critical vulnerabilities including a SharePoint zero-day. Immediate action is recommended to secure systems.

VulnerabilitiesHIGHUpdated: Published:

Original Reporting

SOSophos News

AI Summary

CyberPings AI·Reviewed by Rohit Rana

🎯Basically, Microsoft fixed a lot of security holes in their software this month.

What Happened

On April Patch Tuesday, Microsoft released 163 patches affecting 17 product families. Among these, eight vulnerabilities were classified as Critical severity. Notably, CVE-2026-32201, a SharePoint spoofing vulnerability, is currently under active exploit in the wild. The company estimates that 24 CVEs are likely to be exploited within the next 30 days.

Who's Affected

The patches affect various Microsoft products, including Windows Server, Office, and Microsoft Defender. Users of these products, especially those with Defender enabled, should prioritize updating to mitigate risks from the vulnerabilities.

What Data Was Exposed

The vulnerabilities could potentially allow attackers to execute remote code, elevate privileges, or spoof user identities. For instance, the SharePoint vulnerability could enable unauthorized users to read or modify sensitive data, heightening the risk of social engineering attacks.

What You Should Do

Users and administrators should:

Containment

  • 1.Immediately install the latest patches from Microsoft to protect against known vulnerabilities.
  • 2.Monitor for updates on CVE-2026-32201 and other critical vulnerabilities that may be actively exploited.

Notable Vulnerabilities

CVE-2026-33824

A Critical-severity Remote Code Execution vulnerability with a CVSS score of 9.8 was discovered in the Internet Key Exchange service. Temporary mitigation is advised until the patch is applied.

CVE-2026-33825

This Microsoft Defender vulnerability allows local privilege escalation. It has been publicly disclosed and should be patched promptly.

CVE-2026-32201

The SharePoint vulnerability is a zero-day issue that could allow unauthorized access to sensitive data. Prioritize patching this vulnerability as it is currently being exploited.

Conclusion

April's Patch Tuesday highlights the importance of timely updates in maintaining security. With 251 items of concern this month, including advisories from Adobe and Chrome, users must stay vigilant and proactive in applying these crucial updates.

🔒 Pro Insight

🔒 Pro insight: The high volume of critical vulnerabilities this month signals an urgent need for organizations to enhance their patch management processes.

SOSophos News
Read Original

Related Pings