Full Report
8Critical154Important1Moderate0LowMicrosoft addresses 163 CVEs in the April 2026 Patch Tuesday release, including two zero-day vulnerabilities, one of which was exploited in the wild.Microsoft patched 163 CVEs in its April 2026 Patch Tuesday release, with eight rated critical, 154 rated as important and one rated as moderate. This is the second largest Patch Tuesday release, nearing the record set by the October 2025 Patch Tuesday release with 167 CVEs. Our counts omitted two non-Microsoft CVEs from this month's release.This month’s update includes patches for:.NET.NET and Visual Studio.NET Framework.NET,.NET Framework, Visual StudioApplocker Filter Driver (applockerfltr.sys)Azure Logic AppsAzure Monitor AgentDesktop Window ManagerFunction Discovery Service (fdwsd.dll)GitHub Copilot and Visual Studio CodeMicrosoft Brokering File SystemMicrosoft DefenderMicrosoft Dynamics 365 (on-premises)Microsoft Edge (Chromium-based)Microsoft Graphics ComponentMicrosoft High Performance Compute Pack (HPC)Microsoft Management ConsoleMicrosoft OfficeMicrosoft Office ExcelMicrosoft Office PowerPointMicrosoft Office SharePointMicrosoft Office WordMicrosoft Power AppsMicrosoft PowerShellMicrosoft WindowsMicrosoft Windows Search ComponentMicrosoft Windows SpeechRemote Desktop ClientRole: Windows Hyper-VSQL ServerUniversal Plug and Play (upnp.dll)Windows Active DirectoryWindows Admin CenterWindows Advanced Rasterization PlatformWindows Ancillary Function Driver for WinSockWindows Biometric ServiceWindows BitLockerWindows Boot LoaderWindows Boot ManagerWindows Client Side Caching driver (csc.sys)Windows Cloud Files Mini Filter DriverWindows COMWindows Common Log File System DriverWindows Container Isolation FS Filter DriverWindows Cryptographic ServicesWindows Encrypting File System (EFS)Windows File ExplorerWindows GDIWindows HelloWindows HTTP.sysWindows IKE ExtensionWindows InstallerWindows KerberosWindows KernelWindows Kernel MemoryWindows Local Security Authority Subsystem Service (LSASS)Windows LUAFVWindows Management ServicesWindows OLEWindows Print Spooler ComponentsWindows Projected File SystemWindows Push NotificationsWindows Recovery Environment AgentWindows Redirected Drive BufferingWindows Remote DesktopWindows Remote Desktop Licensing ServiceWindows Remote Procedure CallWindows RPC APIWindows Sensor Data ServiceWindows Server Update ServiceWindows ShellWindows Snipping ToolWindows Speech Brokered ApiWindows SSDP ServiceWindows Storage Spaces ControllerWindows TCP/IPWindows TDI Translation Driver (tdx.sys)Windows Universal Plug and Play (UPnP) Device HostWindows USB Print DriverWindows User Interface CoreWindows Virtualization-Based Security (VBS) EnclaveWindows WalletServiceWindows WFP NDIS Lightweight Filter Driver (wfplwfs.sys)Windows Win32K - GRFXWindows Win32K - ICOMPElevation of privilege (EoP) vulnerabilities accounted for 57.1% of the vulnerabilities patched this month, followed by information disclosure vulnerabilities and remote code execution (RCE) vulnerabilities at 12.3% each.ImportantCVE-2026-20945 and CVE-2026-32201 | Microsoft SharePoint Server Spoofing VulnerabilityCVE-2026-20945 and CVE-2026-32201 are spoofing vulnerabilities affecting Microsoft SharePoint. CVE-2026-20945 received a CVSSv3 score of 4.6, while CVE-2026-32201 received a score of 6.5. According to Microsoft, CVE-2026-32201 was exploited in the wild as a zero-day. Microsoft has released updates for SharePoint 2016, 2019 and SharePoint Server Subscription Edition to address these flaws.ImportantCVE-2026-33825 | Microsoft Defender Elevation of Privilege VulnerabilityCVE-2026-33825 is an EoP vulnerability in Microsoft Defender. It received a CVSSv3 score of 7.8 and was rated important. According to Microsoft, this flaw was publicly disclosed prior to a patch being made available. While Microsoft’s advisory made no mention of public exploit code, the description appears to match a zero-day exploit, known as BlueHammer, with code posted to GitHub on April 3rd. A researcher using the alias "Chaotic Eclipse" released the exploit and expressed concern about Microsoft’s handling of the vulnerability disclosure process.CriticalCVE-2026-33826 | Windows Active Directory Remote Code Execution VulnerabilityCVE-2026-33826 is a RCE vulnerability affecting Windows Active Directory. It received a CVSSv3 score of 8, was rated as critical and was assessed as “Exploitation More Likely” according to Microsoft’s Exploitability Index. Successful exploitation requires an authenticated attacker to send a specially crafted RPC call to a vulnerable RPC host, resulting in code execution with the same permissions as the RPC host. Despite the exploitation assessment and severity, the Microsoft advisory does note that an attacker would need to be in the “same restricted Active Directory domain as the target system” in order to exploit this flaw.CriticalCVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution VulnerabilityCVE-2026-33824 is a RCE affecting Windows Internet Key Exchange (IKE) Service Extensions. It received a CVSSv3 score of 9.8 and was rated as critical. This vulnerability can be exploited by an unauthenticated attacker by sending crafted packets to a target with IKE version 2 enabled. Microsoft’s advisory includes some mitigations that can be applied in the event immediate patching cannot be performed. This includes firewall rules for UDP ports 500 and 4500.ImportantCVE-2026-27913 | Windows BitLocker Security Feature Bypass VulnerabilityCVE-2026-27913 is a security feature bypass vulnerability affecting Windows BitLocker. It received a CVSSv3 score of 7.7 and was rated as important. Successful exploitation could allow an attacker to bypass Secure Boot, a UEFI firmware security feature used to allow only trusted and properly signed software runs during the startup process. While there’s no known exploitation of this vulnerability as of the time this blog was published, Microsoft assesses this vulnerability as “Exploitation More Likely.”ImportantCVE-2026-26151 | Remote Desktop Spoofing VulnerabilityCVE-2026-26151 is a spoofing vulnerability in Remote Desktop. It was assigned a CVSS v3 score of 7.1 and rated important. Microsoft assesses this vulnerability as more likely to be exploited. An attacker could exploit this vulnerability by convincing a target to open a crafted file. This vulnerability was credited to the United Kingdom's National Cyber Security Centre (NCSC).Previously, users would not receive any warning when attempting to open a Remote Desktop Protocol (RDP) file. However, starting with the April 2026 Security Update, users will now receive more sufficient warning dialogues when interacting with potentially malicious RDP files. For more information, visit this link.Tenable SolutionsA list of all the plugins released for Microsoft’s April 2026 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.Get more informationMicrosoft's April 2026 Security UpdatesTenable plugins for Microsoft April 2026 Patch Tuesday Security UpdatesJoin Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Analysis Summary
# Vulnerability: Microsoft April 2026 Patch Tuesday Overview
Microsoft addressed 163 CVEs in this release, featuring 8 Critical and 154 Important vulnerabilities. This represents one of the largest update cycles to date, including two zero-day vulnerabilities.
---
# Vulnerability: Microsoft SharePoint Server Spoofing (Zero-Day)
## CVE Details
- CVE ID: CVE-2026-32201 (and CVE-2026-20945)
- CVSS Score: 6.5 (Important) / 4.6 (Important)
- CWE: Spoofing
## Affected Systems
- Products: Microsoft SharePoint Server
- Versions: SharePoint 2016, SharePoint 2019, and SharePoint Server Subscription Edition
## Vulnerability Description
A spoofing vulnerability exists in Microsoft SharePoint Server that allows an attacker to impersonate legitimate users or services. While specific technical mechanics were not detailed, it typically involves the manipulation of web-based requests to bypass security logic.
## Exploitation
- Status: **Exploited in the wild** (CVE-2026-32201)
- Complexity: Low
- Attack Vector: Network
## Impact
- Confidentiality: Partial
- Integrity: Partial
- Availability: None
## Remediation
### Patches
- Deploy the April 2026 cumulative updates for the specific SharePoint versions listed above.
---
# Vulnerability: Microsoft Defender Elevation of Privilege (BlueHammer)
## CVE Details
- CVE ID: CVE-2026-33825
- CVSS Score: 7.8 (Important)
- CWE: Elevation of Privilege (EoP)
## Affected Systems
- Products: Microsoft Defender
## Vulnerability Description
An elevation of privilege vulnerability referred to as "BlueHammer." It allows a local attacker to escalate privileges to a higher level (likely SYSTEM) by exploiting a flaw in how the Defender service handles internal operations.
## Exploitation
- Status: **Publicly Disclosed / PoC Available** (Code posted to GitHub by researcher "Chaotic Eclipse").
- Complexity: Low
- Attack Vector: Local
## Impact
- Confidentiality: High
- Integrity: High
- Availability: High
## Remediation
### Patches
- Updates are typically delivered automatically via Microsoft Defender engine updates; ensure the client version is updated to the April 2026 release.
---
# Vulnerability: Windows Active Directory Remote Code Execution
## CVE Details
- CVE ID: CVE-2026-33826
- CVSS Score: 8.0 (Critical)
- CWE: Remote Code Execution (RCE)
## Affected Systems
- Products: Windows Active Directory
## Vulnerability Description
An authenticated attacker can execute code with the same permissions as the RPC host. The attack requires sending a specially crafted RPC call to a vulnerable host within the same restricted Active Directory domain.
## Exploitation
- Status: Not exploited (Assessed as "Exploitation More Likely")
- Complexity: Medium (Requires authentication and network proximity)
- Attack Vector: Network
## Impact
- Confidentiality: High
- Integrity: High
- Availability: High
## Remediation
### Patches
- Apply April 2026 OS-level security updates to all Domain Controllers.
---
# Vulnerability: Windows IKE Service Extensions RCE
## CVE Details
- CVE ID: CVE-2026-33824
- CVSS Score: 9.8 (Critical)
- CWE: Remote Code Execution (RCE)
## Affected Systems
- Configurations: Systems with IKE version 2 (IKEv2) enabled.
## Vulnerability Description
An unauthenticated attacker can achieve remote code execution by sending specially crafted packets to a target system running the Internet Key Exchange (IKE) service.
## Exploitation
- Status: Not exploited
- Complexity: Low
- Attack Vector: Network
## Impact
- Confidentiality: High
- Integrity: High
- Availability: High
## Remediation
### Patches
- Apply April 2026 Windows Security Updates.
### Workarounds
- Filter/Block UDP ports 500 and 4500 at the network perimeter if IKEv2 is not required.
---
# Vulnerability: Windows BitLocker Security Feature Bypass
## CVE Details
- CVE ID: CVE-2026-27913
- CVSS Score: 7.7 (Important)
- CWE: Security Feature Bypass
## Affected Systems
- Products: Windows BitLocker / Secure Boot
## Vulnerability Description
Exploitation allows an attacker to bypass Secure Boot, the UEFI firmware security feature. This enables the execution of untrusted or unsigned software during the boot process.
## Exploitation
- Status: Not exploited (Assessed as "Exploitation More Likely")
- Complexity: Medium
- Attack Vector: Local (Requires physical or administrative access to the boot chain)
## Impact
- Integrity: High (Bypass of boot-time security controls)
## Remediation
### Patches
- Apply Windows April 2026 Security Updates. Note that BitLocker/Secure Boot patches often require additional manual steps or multiple reboots to finalize DBX updates.
---
## Detection and General Mitigation
- **Detection**: Use Tenable plugins for "April 2026 Patch Tuesday" to identify vulnerable assets. Monitor for unusual RPC traffic to Domain Controllers or unauthorized IKEv2 packets.
- **References**:
- Microsoft Security Update Guide: hxxps[://]msrc[.]microsoft[.]com/update-guide/en-us/releaseNote/2026-Apr
- Tenable Blog: hxxps[://]www[.]tenable[.]com/blog/microsofts-april-2026-patch-tuesday-addresses-163-cves-cve-2026-32201