FeedVulnerabilityMicrosoft’s April Windows update fixes 165 flaws, one exploi...
VulnerabilityCyber Insider
9.8CRITICAL

Microsoft’s April Windows update fixes 165 flaws, one exploited zero-day

📅 14 April 2026 at 21:11 UTC📰 Cyber InsiderView original source ↗
Microsoft’s April Windows update fixes 165 flaws, one exploited zero-day

Microsoft has released its April 2026 Patch Tuesday updates for Windows 11 versions 24H2 and 25H2, to fix security bugs across the operating system. The security release addresses 165 flaws, including one actively exploited SharePoint spoofing flaw and multiple “more likely to be exploited” Windows bugs affecting core components. The April security updates were published … The post Microsoft’s April Windows update fixes 165 flaws, one exploited zero-day appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Microsoft has released its April 2026 Patch Tuesday updates to fix security bugs across Windows 11 versions 24H2 and 25H2, including one actively exploited SharePoint spoofing flaw. This highlights the importance of regular patching and staying up-to-date with security updates.

⚙️Technical Details
CVEs
CVE-2026-32201CVE-2026-33824CVE-2026-26149CVE-2026-0390CVE-2026-26151
Affected Systems
Windows 11 versions 24H2 and 25H2
Attack Vectors
NETWORKNETWORKNETWORKLOCALNETWORK
💥Impact Assessment
Severity: C
Who Is at Risk
Authorized attackers, potentially with malicious intent
🛡️Recommended Actions
1Apply the April 2026 Patch Tuesday updates to Windows 11 versions 24H2 and 25H2 as soon as possible.
2Disable SharePoint spoofing by configuring proper input validation.
3Keep remote desktop services up-to-date with the latest security patches.
📦Affected Products
Microsoft Sharepoint ServerWindows
🔐NVD Verified DataVERIFIED
CVE-2026-32201CVSS 6.5MEDIUM
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weaknesses
CWE-20
Affected Products (CPE)
Microsoft Sharepoint Server
CVE-2026-33824CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-415
CVE-2026-26149CVSS 9CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weaknesses
CWE-150
CVE-2026-0390CVSS 6.7MEDIUM
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-807
CVE-2026-26151CVSS 7.1HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Weaknesses
CWE-357

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider
← Back to feed