Security News Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days

Gandalf_The_Grey

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Forum Veteran
Apr 24, 2016
7,823
6
83,041
8,389
55
The Netherlands
Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.

This Patch Tuesday also addresses eight "Critical" vulnerabilities, 7 of which are remote code execution flaws and the other is a denial of service flaw.

The number of bugs in each vulnerability category is listed below:
  • 93 Elevation of Privilege Vulnerabilities
  • 13 Security Feature Bypass Vulnerabilities
  • 20 Remote Code Execution Vulnerabilities
  • 21 Information Disclosure Vulnerabilities
  • 10 Denial of Service Vulnerabilities
  • 9 Spoofing Vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today.
 
ZDI: The April 2026 Security Update Review
It’s time once again for Patch Tuesday, and this one is huge. We’ve also got multiple exploits in the wild, which adds another layer of urgency to this month’s release. Take a break from your regularly scheduled activities, and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should be posted within a couple of hours after the release.
Adobe Patches for April 2026

For April, Adobe released 12 bulletins addressing 61 unique CVEs in Adobe Acrobat Reader, InDesign, InCopy, FrameMaker, Connect, ColdFusion, Bridge, Photoshop, Illustrator, Experience Manager Screens, and the Adobe DNG SDK. Three of the Cold Fusion bugs came through the TrendAI ZDI program.

Obviously, the active attack in Reader is the highest priority for this month, but don’t ignore the second bunch of Reader patches. Cold Fusion also gets a deployment priority of 1, so if you’re still running that platform, make sure you get the update. Otherwise, the FrameMaker and Connect patches fix 11 and nine bugs, respectively. InDesign and Experience Manager Screens also have nine CVEs addressed.

Outside of the Reader bug, none of the other bugs fixed by Adobe this month are listed as publicly known or under active attack at the time of release. One of the Reader bugs and Cold Fusion have a deployment priority of one, the other Reader bug has a priority of two, while all of the other updates released by Adobe this month are listed as deployment priority 3.
Microsoft Patches for April 2026

This month, Microsoft released a monstrous 163 new CVEs in Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, SQL Server, Hyper-V Server, BitLocker, and the Windows Wallet Service. Counting the third-party and a huge Chromium release, it brings the total number of CVEs to a staggering 247 updates. Six of these bugs were reported through the TrendAI ZDI program. Eight of these bugs are rated Critical, two are rated as Moderate, and the rest are rated Important in severity.

By my count, this is the second-largest monthly release in Microsoft’s history. There are many things we could speculate on to justify the size, but if Microsoft is like the other programs out there (including ours), they are likely seeing a rise in submissions found by AI tools. For us, our incoming rate has essentially tripled, making triage a challenge, to say the least. Whatever the reason, we have a lot of bugs to deal with this month. I should also point out that the Pwn2Own Berlin occurs next month, and it’s typical for vendors to patch as much as they can before the event.

There is one Microsoft bug listed as under active attack at the time of release, and one other that’s publicly known.
Looking Ahead

I will be in Berlin for the next Patch Tuesday, which will be May 12, and I’ll provide my full thoughts then on what will hopefully be a smaller release than this one. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!
 
Remember guys: don't install this. Just let the Windows install update automatically whenever it's ready. Just because it works for some, doesn't mean it will work for you too.

Windows Update is designed to install automatically once it was confirmed it doesn't break anything on your configuration.
 
Remember guys: don't install this. Just let the Windows install update automatically whenever it's ready. Just because it works for some, doesn't mean it will work for you too.

Windows Update is designed to install automatically once it was confirmed it doesn't break anything on your configuration.
Installed; no problems.

Capture.JPG
 
Bleeping computer said this:
The publicly disclosed zero-day is:

CVE-2026-33825 - Microsoft Defender Elevation of Privilege Vulnerability

Microsoft has patched a Microsoft Defender privilege elevation flaw that gives SYSTEM privileges.

The company has addressed the flaw in the Microsoft Defender Antimalware Platform update version 4.18.26050.3011, which will automatically be downloaded to systems.
The CVE above said this:
ReferencesIdentification
Last version of the Microsoft Defender Antimalware Platform affected by this vulnerabilityVersion 4.18.26020.6
First version of the Microsoft Defender Antimalware Platform with this vulnerability addressedVersion 4.18.26030.3011
So, apparently, Version 4.18.26030.3011 (the one I still get), already has this problem addressed.
 
I see ZDNet tries to hide the severity.
Whereas bleepingcomputer tells it like it is
  • 93 Elevation of Privilege Vulnerabilities
  • 13 Security Feature Bypass Vulnerabilities
  • 20 Remote Code Execution Vulnerabilities
93 EoP !!
20 RCE !!
When the hackers reverse engineer them they'll have a field day.