How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
April 2026 Patch Tuesday: Microsoft fixed 163 vulnerabilities, 8 of them Critical. 2 were already being exploited. Released Tue 14 Apr 2026.
- 163vulnerabilities fixed
- 8Critical
- 2exploited before the fix
- 1publicly disclosed
- 4now on CISA KEV
By type: 93 elevation of privilege, 20 remote code execution, 20 information disclosure, 11 security feature bypass, 9 denial of service, 9 spoofing, 1 tampering.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.
| CVE | What | Severity | CVSS | Why first |
|---|---|---|---|---|
CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution | Critical | 9.8 | On CISA KEV federal deadline 21 Aug |
CVE-2026-33825 | Microsoft Defender Elevation of Privilege | Important | 7.8 | Publicly disclosed On CISA KEV federal deadline 6 May Ransomware |
CVE-2026-32201 | Microsoft SharePoint Server Spoofing | Important | 6.5 | Exploited On CISA KEV federal deadline 28 Apr |
CVE-2026-32202 | Windows Shell Spoofing | Important | 4.3 | Exploited On CISA KEV federal deadline 12 May |
Critical (8)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-32157 | Remote Desktop Client Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-32190 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-33114 | Microsoft Word Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-33115 | Microsoft Word Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-33827 | Windows TCP/IP Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-33826 | Windows Active Directory Remote Code Execution | Remote Code Execution | 8.0 |
CVE-2026-23666 | .NET Framework Denial of Service | Denial of Service | 7.5 |
Added to CISA KEV in April 2026 (31)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2026-41940 | WebPros cPanel & WHM and WP2 (WordPress Squared) | Missing Authentication for Critical Function | 30 Apr | 3 May 2026 | Known |
CVE-2024-1708 | ConnectWise ScreenConnect | Path Traversal | 28 Apr | 12 May 2026 | Known |
CVE-2026-32202 | Microsoft Windows | Protection Mechanism Failure | 28 Apr | 12 May 2026 | |
CVE-2024-57726 | SimpleHelp SimpleHelp | SimpleHelp Missing Authorization | 24 Apr | 8 May 2026 | Known |
CVE-2024-57728 | SimpleHelp SimpleHelp | SimpleHelp Path Traversal | 24 Apr | 8 May 2026 | Known |
CVE-2024-7399 | Samsung MagicINFO 9 Server | Path Traversal | 24 Apr | 8 May 2026 | |
CVE-2025-29635 | D-Link DIR-823X | Command Injection | 24 Apr | 8 May 2026 | |
CVE-2026-39987 | Marimo Marimo | Marimo Remote Code Execution | 23 Apr | 7 May 2026 | |
CVE-2026-33825 | Microsoft Defender | Insufficient Granularity of Access Control | 22 Apr | 6 May 2026 | Known |
CVE-2023-27351 | PaperCut NG/MF | Improper Authentication | 20 Apr | 4 May 2026 | Known |
CVE-2024-27199 | JetBrains TeamCity | Relative Path Traversal | 20 Apr | 4 May 2026 | Known |
CVE-2025-2749 | Kentico Kentico Xperience | Kentico Xperience Path Traversal | 20 Apr | 4 May 2026 | |
CVE-2025-32975 | Quest KACE Systems Management Appliance (SMA) | Improper Authentication | 20 Apr | 4 May 2026 | |
CVE-2025-48700 | Synacor Zimbra Collaboration Suite (ZCS) | Cross-site Scripting | 20 Apr | 23 Apr 2026 | |
CVE-2026-20122 | Cisco Catalyst SD-WAN Manger | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs | 20 Apr | 23 Apr 2026 | |
CVE-2026-20128 | Cisco Catalyst SD-WAN Manager | Storing Passwords in a Recoverable Format | 20 Apr | 23 Apr 2026 | |
CVE-2026-20133 | Cisco Catalyst SD-WAN Manager | Exposure of Sensitive Information to an Unauthorized Actor | 20 Apr | 23 Apr 2026 | |
CVE-2026-34197 | Apache ActiveMQ | Improper Input Validation | 16 Apr | 30 Apr 2026 | |
CVE-2009-0238 | Microsoft Office | Remote Code Execution | 14 Apr | 28 Apr 2026 | |
CVE-2026-32201 | Microsoft SharePoint Server | Improper Input Validation | 14 Apr | 28 Apr 2026 | |
CVE-2012-1854 | Microsoft Visual Basic for Applications (VBA) | Microsoft Visual Basic for Applications Insecure Library Loading | 13 Apr | 27 Apr 2026 | |
CVE-2020-9715 | Adobe Acrobat | Use-After-Free | 13 Apr | 27 Apr 2026 | |
CVE-2023-21529 | Microsoft Exchange Server | Deserialization of Untrusted Data | 13 Apr | 27 Apr 2026 | Known |
CVE-2023-36424 | Microsoft Windows | Out-of-Bounds Read | 13 Apr | 27 Apr 2026 | |
CVE-2025-60710 | Microsoft Windows | Link Following | 13 Apr | 27 Apr 2026 | Known |
CVE-2026-21643 | Fortinet FortiClient EMS | SQL Injection | 13 Apr | 16 Apr 2026 | |
CVE-2026-34621 | Adobe Acrobat and Reader | Prototype Pollution | 13 Apr | 27 Apr 2026 | |
CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) | Code Injection | 8 Apr | 11 Apr 2026 | |
CVE-2026-35616 | Fortinet FortiClient EMS | Improper Access Control | 6 Apr | 9 Apr 2026 | |
CVE-2026-3502 | TrueConf Client | Download of Code Without Integrity Check | 2 Apr | 16 Apr 2026 | |
CVE-2026-5281 | Google Dawn | Use-After-Free | 1 Apr | 15 Apr 2026 |
All 163 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2026-33824 | Windows IKE Extension | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution | Critical | 9.8 |
CVE-2026-32157 | Remote Desktop Client | Remote Desktop Client Remote Code Execution | Critical | 8.8 |
CVE-2026-32190 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2026-33114 | Microsoft Office Word | Microsoft Word Remote Code Execution | Critical | 8.4 |
CVE-2026-33115 | Microsoft Office Word | Microsoft Word Remote Code Execution | Critical | 8.4 |
CVE-2026-33827 | Windows TCP/IP | Windows TCP/IP Remote Code Execution | Critical | 8.1 |
CVE-2026-33826 | Windows Active Directory | Windows Active Directory Remote Code Execution | Critical | 8.0 |
CVE-2026-23666 | .NET Framework | .NET Framework Denial of Service | Critical | 7.5 |
CVE-2026-26149 | Microsoft Power Apps | Microsoft Power Apps Desktop Client Spoofing | Important | 9.0 |
CVE-2026-26167 | Windows Push Notifications | Windows Push Notifications Elevation of Privilege | Important | 8.8 |
CVE-2026-26178 | Windows Advanced Rasterization Platform | Windows Advanced Rasterization Platform Elevation of Privilege | Important | 8.8 |
CVE-2026-32171 | Azure Logic Apps | Azure Logic Apps Elevation of Privilege | Important | 8.8 |
CVE-2026-32225 | Windows Shell | Windows Shell Security Feature Bypass | Important | 8.8 |
CVE-2026-33120 | SQL Server | Microsoft SQL Server Remote Code Execution | Important | 8.8 |
CVE-2026-27928 | Windows Hello | Windows Hello Security Feature Bypass | Important | 8.7 |
CVE-2026-32091 | Microsoft Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 8.4 |
CVE-2026-32162 | Windows COM | Windows COM Elevation of Privilege | Important | 8.4 |
CVE-2026-32221 | Microsoft Graphics Component | Windows Graphics Component Remote Code Execution | Important | 8.4 |
CVE-2026-27912 | Windows Kerberos | Windows Kerberos Elevation of Privilege | Important | 8.0 |
CVE-2026-20930 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-23657 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-26143 | Microsoft PowerShell | Microsoft PowerShell Security Feature Bypass | Important | 7.8 |
CVE-2026-26153 | Windows Encrypting File System (EFS) | Windows Encrypted File System (EFS) Elevation of Privilege | Important | 7.8 |
CVE-2026-26156 | Role: Windows Hyper-V | Windows Hyper-V Remote Code Execution | Important | 7.8 |
CVE-2026-26159 | Windows Remote Desktop Licensing Service | Remote Desktop Licensing Service Elevation of Privilege | Important | 7.8 |
CVE-2026-26160 | Windows Remote Desktop Licensing Service | Remote Desktop Licensing Service Elevation of Privilege | Important | 7.8 |
CVE-2026-26161 | Windows Sensor Data Service | Windows Sensor Data Service Elevation of Privilege | Important | 7.8 |
CVE-2026-26162 | Windows OLE | Windows OLE Elevation of Privilege | Important | 7.8 |
CVE-2026-26163 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-26168 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-26170 | Microsoft PowerShell | PowerShell Elevation of Privilege | Important | 7.8 |
CVE-2026-26172 | Windows Push Notifications | Windows Push Notifications Elevation of Privilege | Important | 7.8 |
CVE-2026-26176 | Windows Client Side Caching driver (csc.sys) | Windows Client Side Caching driver (csc.sys) Elevation of Privilege | Important | 7.8 |
CVE-2026-26179 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-26180 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-26181 | Microsoft Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.8 |
CVE-2026-26183 | Windows RPC API | Remote Access Management service/API (RPC server) Elevation of Privilege | Important | 7.8 |
CVE-2026-26184 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2026-27907 | Windows Storage Spaces Controller | Windows Storage Spaces Controller Elevation of Privilege | Important | 7.8 |
CVE-2026-27909 | Microsoft Windows Search Component | Windows Search Service Elevation of Privilege | Important | 7.8 |
CVE-2026-27910 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-27911 | Windows User Interface Core | Windows User Interface Core Elevation of Privilege | Important | 7.8 |
CVE-2026-27914 | Microsoft Management Console | Microsoft Management Console Elevation of Privilege | Important | 7.8 |
CVE-2026-27915 | Windows Universal Plug and Play (UPnP) Device Host | Windows UPnP Device Host Elevation of Privilege | Important | 7.8 |
CVE-2026-27916 | Windows Universal Plug and Play (UPnP) Device Host | Windows UPnP Device Host Elevation of Privilege | Important | 7.8 |
CVE-2026-27918 | Windows Shell | Windows Shell Elevation of Privilege | Important | 7.8 |
CVE-2026-27919 | Windows Universal Plug and Play (UPnP) Device Host | Windows UPnP Device Host Elevation of Privilege | Important | 7.8 |
CVE-2026-27920 | Windows Universal Plug and Play (UPnP) Device Host | Windows UPnP Device Host Elevation of Privilege | Important | 7.8 |
CVE-2026-27923 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-27924 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-27927 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2026-32069 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2026-32074 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2026-32076 | Windows Storage Spaces Controller | Windows Storage Spaces Controller Elevation of Privilege | Important | 7.8 |
CVE-2026-32077 | Windows Universal Plug and Play (UPnP) Device Host | Windows UPnP Device Host Elevation of Privilege | Important | 7.8 |
CVE-2026-32078 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2026-32089 | Windows Speech Brokered Api | Windows Speech Brokered Api Elevation of Privilege | Important | 7.8 |
CVE-2026-32090 | Windows Speech Brokered Api | Windows Speech Brokered Api Elevation of Privilege | Important | 7.8 |
CVE-2026-32152 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-32153 | Microsoft Windows Speech | Windows Speech Runtime Elevation of Privilege | Important | 7.8 |
CVE-2026-32154 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-32155 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-32158 | Windows Push Notifications | Windows Push Notifications Elevation of Privilege | Important | 7.8 |
CVE-2026-32159 | Windows Push Notifications | Windows Push Notifications Elevation of Privilege | Important | 7.8 |
CVE-2026-32160 | Windows Push Notifications | Windows Push Notifications Elevation of Privilege | Important | 7.8 |
CVE-2026-32163 | Windows User Interface Core | Windows User Interface Core Elevation of Privilege | Important | 7.8 |
CVE-2026-32164 | Windows User Interface Core | Windows User Interface Core Elevation of Privilege | Important | 7.8 |
CVE-2026-32165 | Windows User Interface Core | Windows User Interface Core Elevation of Privilege | Important | 7.8 |
CVE-2026-32168 | Azure Monitor Agent | Azure Monitor Agent Elevation of Privilege | Important | 7.8 |
CVE-2026-32183 | Windows Snipping Tool | Windows Snipping Tool Remote Code Execution | Important | 7.8 |
CVE-2026-32184 | Microsoft High Performance Compute Pack (HPC) | Microsoft High Performance Compute (HPC) Pack Elevation of Privilege | Important | 7.8 |
CVE-2026-32189 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-32192 | Azure Monitor Agent | Azure Monitor Agent Elevation of Privilege | Important | 7.8 |
CVE-2026-32197 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-32198 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-32199 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-32200 | Microsoft Office PowerPoint | Microsoft PowerPoint Remote Code Execution | Important | 7.8 |
CVE-2026-32222 | Windows Win32K – ICOMP | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-33095 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-33098 | Windows Container Isolation FS Filter Driver | Windows Container Isolation FS Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-33101 | Windows Print Spooler Components | Windows Print Spooler Elevation of Privilege | Important | 7.8 |
CVE-2026-33825 | Microsoft Defender | Microsoft Defender Elevation of Privilege | Important | 7.8 |
CVE-2026-27913 | Windows BitLocker | Windows BitLocker Security Feature Bypass | Important | 7.7 |
CVE-2026-26154 | Windows Server Update Service | Windows Server Update Service (WSUS) Tampering | Important | 7.5 |
CVE-2026-26171 | .NET | .NET Denial of Service | Important | 7.5 |
CVE-2026-32071 | Windows Local Security Authority Subsystem Service (LSASS) | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service | Important | 7.5 |
CVE-2026-32178 | .NET | .NET Spoofing | Important | 7.5 |
CVE-2026-32203 | .NET and Visual Studio | .NET and Visual Studio Denial of Service | Important | 7.5 |
CVE-2026-33096 | Windows HTTP.sys | HTTP.sys Denial of Service | Important | 7.5 |
CVE-2026-33116 | .NET, .NET Framework, Visual Studio | .NET, .NET Framework, and Visual Studio Denial of Service | Important | 7.5 |
CVE-2026-32156 | Windows Universal Plug and Play (UPnP) Device Host | Windows UPnP Device Host Remote Code Execution | Important | 7.4 |
CVE-2026-32149 | Role: Windows Hyper-V | Windows Hyper-V Remote Code Execution | Important | 7.3 |
CVE-2026-26151 | Windows Remote Desktop | Remote Desktop Spoofing | Important | 7.1 |
CVE-2026-32188 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 7.1 |
CVE-2026-25184 | Applocker Filter Driver (applockerfltr.sys) | Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege | Important | 7.0 |
CVE-2026-26152 | Windows Cryptographic Services | Microsoft Cryptographic Services Elevation of Privilege | Important | 7.0 |
CVE-2026-26165 | Windows Shell | Windows Shell Elevation of Privilege | Important | 7.0 |
CVE-2026-26166 | Windows Shell | Windows Shell Elevation of Privilege | Important | 7.0 |
CVE-2026-26173 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-26174 | Windows Server Update Service | Windows Server Update Service (WSUS) Elevation of Privilege | Important | 7.0 |
CVE-2026-26177 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-26182 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-27908 | Windows TDI Translation Driver (tdx.sys) | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege | Important | 7.0 |
CVE-2026-27917 | Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) | Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege | Important | 7.0 |
CVE-2026-27921 | Windows TCP/IP | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege | Important | 7.0 |
CVE-2026-27922 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-27926 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-27929 | Windows LUAFV | Windows LUA File Virtualization Filter Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-32068 | Windows SSDP Service | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege | Important | 7.0 |
CVE-2026-32070 | Windows Common Log File System Driver | Windows Common Log File System Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-32073 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-32075 | Windows Universal Plug and Play (UPnP) Device Host | Windows UPnP Device Host Elevation of Privilege | Important | 7.0 |
CVE-2026-32080 | Windows WalletService | Windows WalletService Elevation of Privilege | Important | 7.0 |
CVE-2026-32082 | Windows SSDP Service | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege | Important | 7.0 |
CVE-2026-32083 | Windows SSDP Service | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege | Important | 7.0 |
CVE-2026-32086 | Function Discovery Service (fdwsd.dll) | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege | Important | 7.0 |
CVE-2026-32087 | Function Discovery Service (fdwsd.dll) | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege | Important | 7.0 |
CVE-2026-32093 | Function Discovery Service (fdwsd.dll) | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege | Important | 7.0 |
CVE-2026-32150 | Function Discovery Service (fdwsd.dll) | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege | Important | 7.0 |
CVE-2026-32195 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-32219 | Microsoft Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.0 |
CVE-2026-32224 | Windows Server Update Service | Windows Server Update Service (WSUS) Elevation of Privilege | Important | 7.0 |
CVE-2026-33099 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-33100 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-33104 | Windows Win32K – GRFX | Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-32223 | Windows USB Print Driver | Windows USB Printing Stack (usbprint.sys) Elevation of Privilege | Important | 6.8 |
CVE-2026-0390 | Windows Boot Loader | UEFI Secure Boot Security Feature Bypass | Important | 6.7 |
CVE-2026-32167 | SQL Server | SQL Server Elevation of Privilege | Important | 6.7 |
CVE-2026-32176 | SQL Server | SQL Server Elevation of Privilege | Important | 6.7 |
CVE-2026-26155 | Windows Local Security Authority Subsystem Service (LSASS) | Microsoft Local Security Authority Subsystem Service Information Disclosure | Important | 6.5 |
CVE-2026-27925 | Windows Universal Plug and Play (UPnP) Device Host | Windows UPnP Device Host Information Disclosure | Important | 6.5 |
CVE-2026-32151 | Windows Shell | Windows Shell Information Disclosure | Important | 6.5 |
CVE-2026-32201 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 6.5 |
CVE-2026-32072 | Windows Active Directory | Active Directory Spoofing | Important | 6.2 |
CVE-2026-26169 | Windows Kernel Memory | Windows Kernel Memory Information Disclosure | Important | 6.1 |
CVE-2026-32088 | Windows Biometric Service | Windows Biometric Service Security Feature Bypass | Important | 6.1 |
CVE-2026-32196 | Windows Admin Center | Windows Admin Center Spoofing | Important | 6.1 |
CVE-2026-33822 | Microsoft Office Word | Microsoft Word Information Disclosure | Important | 6.1 |
CVE-2026-32226 | .NET Framework | .NET Framework Denial of Service | Important | 5.9 |
CVE-2026-23653 | GitHub Copilot and Visual Studio Code | GitHub Copilot and Visual Studio Code Information Disclosure | Important | 5.7 |
CVE-2026-23670 | Windows Virtualization-Based Security (VBS) Enclave | Windows Virtualization-Based Security (VBS) Security Feature Bypass | Important | 5.7 |
CVE-2026-20806 | Windows COM | Windows COM Server Information Disclosure | Important | 5.5 |
CVE-2026-27930 | Windows GDI | Windows GDI Information Disclosure | Important | 5.5 |
CVE-2026-27931 | Windows GDI | Windows GDI Information Disclosure | Important | 5.5 |
CVE-2026-32079 | Windows File Explorer | Web Account Manager Information Disclosure | Important | 5.5 |
CVE-2026-32081 | Windows File Explorer | Package Catalog Information Disclosure | Important | 5.5 |
CVE-2026-32084 | Windows File Explorer | Windows Print Spooler Information Disclosure | Important | 5.5 |
CVE-2026-32085 | Windows Remote Procedure Call | Remote Procedure Call Information Disclosure | Important | 5.5 |
CVE-2026-32181 | Microsoft Windows | Connected User Experiences and Telemetry Service Denial of Service | Important | 5.5 |
CVE-2026-32212 | Universal Plug and Play (upnp.dll) | Universal Plug and Play (upnp.dll) Information Disclosure | Important | 5.5 |
CVE-2026-32214 | Universal Plug and Play (upnp.dll) | Universal Plug and Play (upnp.dll) Information Disclosure | Important | 5.5 |
CVE-2026-32215 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2026-32217 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2026-32218 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2026-33103 | Microsoft Dynamics 365 (on-premises) | Microsoft Dynamics 365 (On-Premises) Information Disclosure | Important | 5.5 |
CVE-2026-20928 | Windows Recovery Environment Agent | Windows Recovery Environment Security Feature Bypass | Important | 4.6 |
CVE-2026-20945 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-26175 | Windows Boot Manager | Windows Boot Manager Security Feature Bypass | Important | 4.6 |
CVE-2026-27906 | Windows Hello | Windows Hello Security Feature Bypass | Important | 4.4 |
CVE-2026-32220 | Windows Virtualization-Based Security (VBS) Enclave | UEFI Secure Boot Security Feature Bypass | Important | 4.4 |
CVE-2026-32202 | Windows Shell | Windows Shell Spoofing | Important | 4.3 |
CVE-2026-32216 | Windows Redirected Drive Buffering | Windows Redirected Drive Buffering System Denial of Service | Moderate | 5.5 |
CVE-2026-33829 | Windows Snipping Tool | Windows Snipping Tool Spoofing | Moderate | 4.3 |
Published later in the month (18)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 2 Apr | CVE-2026-32186 | Microsoft Bing Elevation of Privilege | Critical | Fixed by Microsoft |
| 2 Apr | CVE-2026-32213 | Azure AI Foundry Elevation of Privilege | Critical | Fixed by Microsoft |
| 2 Apr | CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege | Critical | Fixed by Microsoft |
| 2 Apr | CVE-2026-33107 | Azure Databricks Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Apr | CVE-2026-33819 | Microsoft Bing Remote Code Execution | Critical | Fixed by Microsoft |
| 23 Apr | CVE-2026-35431 | Microsoft Entra ID Entitlement Management Spoofing | Critical | Fixed by Microsoft |
| 23 Apr | CVE-2026-21515 | Azure IoT Central Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Apr | CVE-2026-24303 | Microsoft Partner Center Elevation of Privilege | Critical | Fixed by Microsoft |
| 2 Apr | CVE-2026-26135 | Azure Custom Locations Resource Provider (RP) Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Apr | CVE-2026-32210 | Microsoft Dynamics 365 (online) Spoofing | Critical | Fixed by Microsoft |
| 23 Apr | CVE-2026-33102 | Microsoft 365 Copilot Elevation of Privilege | Critical | Fixed by Microsoft |
| 2 Apr | CVE-2026-32211 | Azure MCP Server Information Disclosure | Critical | Fixed by Microsoft |
| 23 Apr | CVE-2026-26150 | Microsoft Purview eDiscovery Elevation of Privilege | Critical | Fixed by Microsoft |
| 2 Apr | CVE-2026-32173 | Azure SRE Agent Information Disclosure | Critical | Fixed by Microsoft |
| 23 Apr | CVE-2026-32172 | Microsoft Power Apps Remote Code Execution | Critical | Fixed by Microsoft |
| 21 Apr | CVE-2026-40372 | ASP.NET Core Elevation of Privilege | Important | Update |
| 10 Apr | CVE-2026-33119 | Microsoft Edge (Chromium-based) for Android Spoofing | Moderate | Update |
| 10 Apr | CVE-2026-33118 | Microsoft Edge (Chromium-based) Spoofing | Low | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 2 days ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.