Summary
Microsoft’s April 2026 Patch Tuesday, released on April 14, addressed a massive 167 vulnerabilities across Windows and other Microsoft products — one of the largest monthly patch drops in recent memory. The update includes fixes for eight critical flaws and two zero-day vulnerabilities, one of which was already being exploited in the wild.
The actively exploited zero-day, CVE-2026-32201, is a spoofing vulnerability in Microsoft SharePoint Server caused by improper input validation. It allows unauthenticated attackers to view or modify sensitive information over a network. The second zero-day, CVE-2026-33825, is an elevation of privilege flaw in Microsoft Defender that was publicly disclosed before the patch.
Critical remote code execution vulnerabilities were also patched in Remote Desktop Client (CVE-2026-32157), Windows Active Directory (CVE-2026-33826), Windows TCP/IP (CVE-2026-33827), and the Windows IKE Service (CVE-2026-33824). Additionally, CISA flagged CVE-2026-32202, a zero-click NTLM hash leak vulnerability in Windows Shell, ordering federal agencies to patch by May 12.
Sources
- CrowdStrike — Patch Tuesday Analysis April 2026
- Rapid7 — Patch Tuesday April 2026
- BleepingComputer — CISA Orders Feds to Patch Windows Flaw
Commentary
167 vulnerabilities in a single Patch Tuesday is staggering, and the diversity of critical RCE targets — Active Directory, TCP/IP, Remote Desktop, IKE — reads like an attacker’s wish list of enterprise infrastructure components. The SharePoint zero-day being actively exploited before the patch is particularly concerning given how widely deployed SharePoint is across government and enterprise environments.
The CISA KEV addition of the zero-click NTLM hash leak (CVE-2026-32202) deserves special attention. NTLM relay attacks remain one of the most reliable lateral movement techniques in Active Directory environments, and a zero-click variant significantly lowers the bar. If you’re still running NTLM in production, this is yet another reason to accelerate the migration to Kerberos-only authentication. Patch immediately — the May 12 CISA deadline applies to federal agencies, but everyone else should treat it as equally urgent.
