Microsoft April 2026 Patch Tuesday — 167 Flaws, 2 Zero-Days (SharePoint Spoofing CVE-2026-32201 + Defender EoP CVE-2026-33825)

Microsoft April 2026 Patch Tuesday (TL-2026-0362), also tracked as April 2026 Patch Tuesday, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-04-14. It has no confirmed attribution, affects Microsoft SharePoint Server, references 10 CVEs (CVE-2026-32201, CVE-2026-33825, CVE-2026-23666), maps to 16 MITRE ATT&CK techniques (T1021.001, T1068, T1071.001), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-0362

Threat ID
TL-2026-0362
Also known as
April 2026 Patch Tuesday, MSRC April 2026, Microsoft April 2026 Security Update, KB5082200 Rollup
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
2026-04-14
Last reviewed
2026-04-14
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, legal, manufacturing, financial, healthcare, technology, education, defense
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
15

Microsoft's April 2026 Patch Tuesday addresses 167 vulnerabilities including two zero-days — CVE-2026-32201, a SharePoint Server spoofing flaw actively exploited in the wild, and CVE-2026-33825, a publicly disclosed Microsoft Defender Antimalware Platform elevation-of-privilege bug. The release also includes eight critical-rated remote code execution vulnerabilities impacting Office/Word, .NET, Remote Desktop Client, Active Directory, IKE Service, and the Windows TCP/IP stack. Windows 10 end-of-life systems receive coverage through the KB5082200 Extended Security Update.

How Microsoft April 2026 Patch Tuesday works

On April 14, 2026, Microsoft published the largest Patch Tuesday rollup of the year, remediating 167 distinct vulnerabilities across Windows, Office, SharePoint, .NET, Defender, Active Directory, Remote Desktop, Azure, Hyper-V, and supporting components. The release is notable for two zero-day entries and eight Critical-severity remote code execution bugs, several of which are wormable or trivially exploitable over the network.

Zero-Day #1 — CVE-2026-32201 (SharePoint Server Spoofing, CVSS 8.8, Actively Exploited): An improper authentication flaw in the SharePoint Server web front-end permits an unauthenticated remote attacker to craft a forged request that impersonates an authenticated user, enabling session hijack, data read, and subsequent uploads of malicious content. Microsoft's MSRC advisory and multiple incident-response vendors confirmed in-the-wild exploitation against enterprise SharePoint farms during the 30 days prior to release, with activity clustered against government, legal, and manufacturing verticals in North America and Europe. Observed post-exploitation behavior includes web-shell deployment (spinstall.aspx variants), credential harvesting from the SharePoint hive, and pivoting to the SQL backend via integrated Windows auth.

Zero-Day #2 — CVE-2026-33825 (Microsoft Defender Antimalware Platform EoP, CVSS 7.8, Publicly Disclosed): A TOCTOU race condition in the Defender update orchestrator allows a local low-privileged user to write an arbitrary file as SYSTEM via a symbolic-link hijack of the platform update staging directory. Proof-of-concept code was published to GitHub prior to Microsoft's advisory; no in-the-wild exploitation had been confirmed at release time, but the bug is trivial to weaponize and is expected to appear in commodity post-exploitation toolkits within days.

Critical RCE Highlights: - CVE-2026-23666 — Windows TCP/IP IPv6 RCE (CVSS 9.8): Integer overflow in IPv6 fragment reassembly reachable from any adjacent network; rated wormable by MSRC. - CVE-2026-32190 — Microsoft Word RCE (CVSS 8.4): Preview Pane attack vector; opening or previewing a crafted .docx triggers heap corruption. - CVE-2026-33115 — .NET and Visual Studio RCE (CVSS 8.1): Unsafe deserialization in BinaryFormatter fallback path. - CVE-2026-33114 — Remote Desktop Client RCE (CVSS 8.8): Client-side parsing flaw triggered by connecting to a rogue RDP server. - CVE-2026-32157 — Active Directory Domain Services RCE (CVSS 9.0): Authenticated low-priv attacker writes arbitrary LDAP attributes leading to DC code execution. - CVE-2026-33826 — Windows IKE Extensions RCE (CVSS 9.1): Malformed IKE_SA_INIT packet triggers stack overflow in IKEEXT. - CVE-2026-33824 — Office/Outlook RCE (CVSS 8.4): Preview of a crafted email triggers OLE object handling bug. - CVE-2026-33827 — SharePoint Server RCE (CVSS 8.8): Deserialization in workflow engine, chained by threat actors with the CVE-2026-32201 spoof.

Windows 10 Coverage: Although Windows 10 reached end-of-support in October 2025, Microsoft shipped KB5082200 as part of the Extended Security Update program, raising builds to 19045.7184 (22H2) and 19044.7184 (21H2 LTSC). The ESU is gated behind a commercial ESU license key but is broadly available to Volume Licensing and CSP customers.

MITRE ATT&CK techniques used in TL-2026-0362

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1210 Exploitation of Remote Services

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Application Layer Protocol: Web Protocols

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing; T1566.001 Spearphishing Attachment

Execution

T1203 Exploitation for Client Execution; T1204.002 User Execution: Malicious File

Discovery

T1482 Domain Trust Discovery

Persistence

T1505.003 Server Software Component: Web Shell

Credential Access

T1552.001 Unsecured Credentials: Credentials In Files; T1555 Credentials from Password Stores

Impact

T1565 Data Manipulation

stealth

T1574.005 Executable Installer File Permissions Weakness

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Microsoft April 2026 Patch Tuesday

  • Microsoft — SharePoint Server
    Vulnerable versions: Subscription Edition; 2019; 2016
    Fixed in: April 2026 SU
  • Microsoft — Windows 10
    Vulnerable versions: 22H2 < 19045.7184; 21H2 LTSC < 19044.7184
    Fixed in: KB5082200
  • Microsoft — Windows 11
    Vulnerable versions: 22H2; 23H2; 24H2
    Fixed in: KB5082140; KB5082155
  • Microsoft — Windows Server
    Vulnerable versions: 2019; 2022; 2025
    Fixed in: April 2026 cumulative
  • Microsoft — Microsoft Defender Antimalware Platform
    Vulnerable versions: < 4.18.26040.x
    Fixed in: 4.18.26040.x
  • Microsoft — Microsoft Word / Office
    Vulnerable versions: Office LTSC 2024; Microsoft 365 Apps < April 2026 channel
    Fixed in: April 2026 channel
  • Microsoft — .NET
    Vulnerable versions: 6.0 < 6.0.33; 8.0 < 8.0.15; 9.0 < 9.0.4
    Fixed in: 6.0.33; 8.0.15; 9.0.4
  • Microsoft — Remote Desktop Client
    Vulnerable versions: Windows MSTSC client all supported
    Fixed in: April 2026 cumulative

Remediation for Microsoft April 2026 Patch Tuesday

Patches

  • KB5082200 — Windows 10 22H2 / 21H2 LTSC (build 19045.7184 / 19044.7184) ESU
  • KB5082140 — Windows 11 23H2 / 22H2 cumulative
  • KB5082155 — Windows 11 24H2 cumulative
  • KB5082300 — Windows Server 2022 cumulative
  • SharePoint Server Subscription Edition April 2026 Security Update
  • Office LTSC 2024 / Microsoft 365 Apps April 2026 channel build
  • .NET 6.0.33 / 8.0.15 / 9.0.4 servicing releases

Immediate actions

  • Apply April 2026 Patch Tuesday updates across all Windows, Office, SharePoint, .NET, and Defender systems within the 72-hour SLA for CISA BOD 22-01 candidates
  • Prioritize SharePoint Server patching for CVE-2026-32201 — this bug is actively exploited
  • Block inbound SharePoint traffic from untrusted sources at the WAF until patching completes
  • Restrict outbound RDP to known-good hosts to mitigate CVE-2026-33114 client-side RCE
  • Disable Outlook Preview Pane via group policy until CVE-2026-33824 patch is validated

Workarounds

  • SharePoint: disable anonymous access and enforce modern authentication on all web applications
  • Defender: monitor C:\ProgramData\Microsoft\Windows Defender\Platform for symlink creations
  • Outlook: disable automatic external content download and set preview pane to off
  • RDP Client: block outbound TCP/3389 at host firewall except to known jump hosts

Longer-term hardening

  • Deploy EDR with behavioral detection for SharePoint web-shell deployment patterns (spinstall.aspx and variants)
  • Enable Defender Tamper Protection to mitigate future local EoP exploitation paths
  • Segment Active Directory tier-0 systems and enforce LDAP signing and channel binding
  • Implement IKE/IPsec egress filtering and rate-limiting to reduce IKEEXT stack exposure
  • Subscribe to Windows 10 ESU for any remaining Win10 endpoints until migration to Windows 11 completes

CVEs associated with Microsoft April 2026 Patch Tuesday

CVE-2026-32201, CVE-2026-33825, CVE-2026-23666, CVE-2026-32190, CVE-2026-33115, CVE-2026-33114, CVE-2026-32157, CVE-2026-33826, CVE-2026-33824, CVE-2026-33827

Weaknesses (CWE) in Microsoft April 2026 Patch Tuesday

CWE-287, CWE-367, CWE-502, CWE-190, CWE-121, CWE-122, CWE-59, CWE-20

Timeline of Microsoft April 2026 Patch Tuesday

  • First observed in-the-wild exploitation of CVE-2026-32201 against a North American legal-sector SharePoint farm per Microsoft Threat Intelligence
  • Microsoft Security Response Center opens case for SharePoint spoofing vulnerability after coordinated report
  • Public proof-of-concept for Microsoft Defender Antimalware Platform EoP (CVE-2026-33825) published to GitHub by independent researcher
  • CISA notifies federal agencies of pending critical Patch Tuesday containing actively exploited zero-day
  • CISA adds CVE-2026-32201 to the Known Exploited Vulnerabilities catalog with a 21-day federal remediation deadline
  • Windows 10 Extended Security Update KB5082200 released raising build to 19045.7184 / 19044.7184
  • Microsoft publishes April 2026 Patch Tuesday addressing 167 CVEs including two zero-days and eight Critical RCEs
  • Mass-scanning for vulnerable SharePoint front-ends observed by multiple honeypot networks within 24 hours of disclosure
  • As of 2026-05-29, patches shipped April 14 but the actively-exploited SharePoint zero-day CVE-2026-32201 (CISA KEV, April 28 deadline) remains a live concern, with 1,300+ internet-facing servers still unpatched and under ongoing attack post-deadline. Defender EoP CVE-2026-33825 had a public PoC, so exploitation risk persists against the unpatched fleet.

Sources cited for Microsoft April 2026 Patch Tuesday

Threats related to Microsoft April 2026 Patch Tuesday

Detection coverage for TL-2026-0362

As of 2026-04-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0362 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats