Microsoft April 2026 Patch Tuesday — 167 Flaws, 2 Zero-Days (SharePoint Spoofing CVE-2026-32201 + Defender EoP CVE-2026-33825)
Microsoft April 2026 Patch Tuesday (TL-2026-0362), also tracked as April 2026 Patch Tuesday, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-04-14. It has no confirmed attribution, affects Microsoft SharePoint Server, references 10 CVEs (CVE-2026-32201, CVE-2026-33825, CVE-2026-23666), maps to 16 MITRE ATT&CK techniques (T1021.001, T1068, T1071.001), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-0362
- Threat ID
- TL-2026-0362
- Also known as
- April 2026 Patch Tuesday, MSRC April 2026, Microsoft April 2026 Security Update, KB5082200 Rollup
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- 2026-04-14
- Last reviewed
- 2026-04-14
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, legal, manufacturing, financial, healthcare, technology, education, defense
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 15
Microsoft's April 2026 Patch Tuesday addresses 167 vulnerabilities including two zero-days — CVE-2026-32201, a SharePoint Server spoofing flaw actively exploited in the wild, and CVE-2026-33825, a publicly disclosed Microsoft Defender Antimalware Platform elevation-of-privilege bug. The release also includes eight critical-rated remote code execution vulnerabilities impacting Office/Word, .NET, Remote Desktop Client, Active Directory, IKE Service, and the Windows TCP/IP stack. Windows 10 end-of-life systems receive coverage through the KB5082200 Extended Security Update.
How Microsoft April 2026 Patch Tuesday works
On April 14, 2026, Microsoft published the largest Patch Tuesday rollup of the year, remediating 167 distinct vulnerabilities across Windows, Office, SharePoint, .NET, Defender, Active Directory, Remote Desktop, Azure, Hyper-V, and supporting components. The release is notable for two zero-day entries and eight Critical-severity remote code execution bugs, several of which are wormable or trivially exploitable over the network.
Zero-Day #1 — CVE-2026-32201 (SharePoint Server Spoofing, CVSS 8.8, Actively Exploited): An improper authentication flaw in the SharePoint Server web front-end permits an unauthenticated remote attacker to craft a forged request that impersonates an authenticated user, enabling session hijack, data read, and subsequent uploads of malicious content. Microsoft's MSRC advisory and multiple incident-response vendors confirmed in-the-wild exploitation against enterprise SharePoint farms during the 30 days prior to release, with activity clustered against government, legal, and manufacturing verticals in North America and Europe. Observed post-exploitation behavior includes web-shell deployment (spinstall.aspx variants), credential harvesting from the SharePoint hive, and pivoting to the SQL backend via integrated Windows auth.
Zero-Day #2 — CVE-2026-33825 (Microsoft Defender Antimalware Platform EoP, CVSS 7.8, Publicly Disclosed): A TOCTOU race condition in the Defender update orchestrator allows a local low-privileged user to write an arbitrary file as SYSTEM via a symbolic-link hijack of the platform update staging directory. Proof-of-concept code was published to GitHub prior to Microsoft's advisory; no in-the-wild exploitation had been confirmed at release time, but the bug is trivial to weaponize and is expected to appear in commodity post-exploitation toolkits within days.
Critical RCE Highlights: - CVE-2026-23666 — Windows TCP/IP IPv6 RCE (CVSS 9.8): Integer overflow in IPv6 fragment reassembly reachable from any adjacent network; rated wormable by MSRC. - CVE-2026-32190 — Microsoft Word RCE (CVSS 8.4): Preview Pane attack vector; opening or previewing a crafted .docx triggers heap corruption. - CVE-2026-33115 — .NET and Visual Studio RCE (CVSS 8.1): Unsafe deserialization in BinaryFormatter fallback path. - CVE-2026-33114 — Remote Desktop Client RCE (CVSS 8.8): Client-side parsing flaw triggered by connecting to a rogue RDP server. - CVE-2026-32157 — Active Directory Domain Services RCE (CVSS 9.0): Authenticated low-priv attacker writes arbitrary LDAP attributes leading to DC code execution. - CVE-2026-33826 — Windows IKE Extensions RCE (CVSS 9.1): Malformed IKE_SA_INIT packet triggers stack overflow in IKEEXT. - CVE-2026-33824 — Office/Outlook RCE (CVSS 8.4): Preview of a crafted email triggers OLE object handling bug. - CVE-2026-33827 — SharePoint Server RCE (CVSS 8.8): Deserialization in workflow engine, chained by threat actors with the CVE-2026-32201 spoof.
Windows 10 Coverage: Although Windows 10 reached end-of-support in October 2025, Microsoft shipped KB5082200 as part of the Extended Security Update program, raising builds to 19045.7184 (22H2) and 19044.7184 (21H2 LTSC). The ESU is gated behind a commercial ESU license key but is broadly available to Volume Licensing and CSP customers.
MITRE ATT&CK techniques used in TL-2026-0362
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1210 Exploitation of Remote Services
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing; T1566.001 Spearphishing Attachment
Execution
T1203 Exploitation for Client Execution; T1204.002 User Execution: Malicious File
Discovery
Persistence
T1505.003 Server Software Component: Web Shell
Credential Access
T1552.001 Unsecured Credentials: Credentials In Files; T1555 Credentials from Password Stores
Impact
stealth
T1574.005 Executable Installer File Permissions Weakness
defense-impairment
Affected products and versions in Microsoft April 2026 Patch Tuesday
- Microsoft — SharePoint Server
Vulnerable versions: Subscription Edition; 2019; 2016
Fixed in: April 2026 SU - Microsoft — Windows 10
Vulnerable versions: 22H2 < 19045.7184; 21H2 LTSC < 19044.7184
Fixed in: KB5082200 - Microsoft — Windows 11
Vulnerable versions: 22H2; 23H2; 24H2
Fixed in: KB5082140; KB5082155 - Microsoft — Windows Server
Vulnerable versions: 2019; 2022; 2025
Fixed in: April 2026 cumulative - Microsoft — Microsoft Defender Antimalware Platform
Vulnerable versions: < 4.18.26040.x
Fixed in: 4.18.26040.x - Microsoft — Microsoft Word / Office
Vulnerable versions: Office LTSC 2024; Microsoft 365 Apps < April 2026 channel
Fixed in: April 2026 channel - Microsoft — .NET
Vulnerable versions: 6.0 < 6.0.33; 8.0 < 8.0.15; 9.0 < 9.0.4
Fixed in: 6.0.33; 8.0.15; 9.0.4 - Microsoft — Remote Desktop Client
Vulnerable versions: Windows MSTSC client all supported
Fixed in: April 2026 cumulative
Remediation for Microsoft April 2026 Patch Tuesday
Patches
- KB5082200 — Windows 10 22H2 / 21H2 LTSC (build 19045.7184 / 19044.7184) ESU
- KB5082140 — Windows 11 23H2 / 22H2 cumulative
- KB5082155 — Windows 11 24H2 cumulative
- KB5082300 — Windows Server 2022 cumulative
- SharePoint Server Subscription Edition April 2026 Security Update
- Office LTSC 2024 / Microsoft 365 Apps April 2026 channel build
- .NET 6.0.33 / 8.0.15 / 9.0.4 servicing releases
Immediate actions
- Apply April 2026 Patch Tuesday updates across all Windows, Office, SharePoint, .NET, and Defender systems within the 72-hour SLA for CISA BOD 22-01 candidates
- Prioritize SharePoint Server patching for CVE-2026-32201 — this bug is actively exploited
- Block inbound SharePoint traffic from untrusted sources at the WAF until patching completes
- Restrict outbound RDP to known-good hosts to mitigate CVE-2026-33114 client-side RCE
- Disable Outlook Preview Pane via group policy until CVE-2026-33824 patch is validated
Workarounds
- SharePoint: disable anonymous access and enforce modern authentication on all web applications
- Defender: monitor C:\ProgramData\Microsoft\Windows Defender\Platform for symlink creations
- Outlook: disable automatic external content download and set preview pane to off
- RDP Client: block outbound TCP/3389 at host firewall except to known jump hosts
Longer-term hardening
- Deploy EDR with behavioral detection for SharePoint web-shell deployment patterns (spinstall.aspx and variants)
- Enable Defender Tamper Protection to mitigate future local EoP exploitation paths
- Segment Active Directory tier-0 systems and enforce LDAP signing and channel binding
- Implement IKE/IPsec egress filtering and rate-limiting to reduce IKEEXT stack exposure
- Subscribe to Windows 10 ESU for any remaining Win10 endpoints until migration to Windows 11 completes
CVEs associated with Microsoft April 2026 Patch Tuesday
CVE-2026-32201, CVE-2026-33825, CVE-2026-23666, CVE-2026-32190, CVE-2026-33115, CVE-2026-33114, CVE-2026-32157, CVE-2026-33826, CVE-2026-33824, CVE-2026-33827
Weaknesses (CWE) in Microsoft April 2026 Patch Tuesday
CWE-287, CWE-367, CWE-502, CWE-190, CWE-121, CWE-122, CWE-59, CWE-20
Timeline of Microsoft April 2026 Patch Tuesday
- First observed in-the-wild exploitation of CVE-2026-32201 against a North American legal-sector SharePoint farm per Microsoft Threat Intelligence
- Microsoft Security Response Center opens case for SharePoint spoofing vulnerability after coordinated report
- Public proof-of-concept for Microsoft Defender Antimalware Platform EoP (CVE-2026-33825) published to GitHub by independent researcher
- CISA notifies federal agencies of pending critical Patch Tuesday containing actively exploited zero-day
- CISA adds CVE-2026-32201 to the Known Exploited Vulnerabilities catalog with a 21-day federal remediation deadline
- Windows 10 Extended Security Update KB5082200 released raising build to 19045.7184 / 19044.7184
- Microsoft publishes April 2026 Patch Tuesday addressing 167 CVEs including two zero-days and eight Critical RCEs
- Mass-scanning for vulnerable SharePoint front-ends observed by multiple honeypot networks within 24 hours of disclosure
- As of 2026-05-29, patches shipped April 14 but the actively-exploited SharePoint zero-day CVE-2026-32201 (CISA KEV, April 28 deadline) remains a live concern, with 1,300+ internet-facing servers still unpatched and under ongoing attack post-deadline. Defender EoP CVE-2026-33825 had a public PoC, so exploitation risk persists against the unpatched fleet.
Sources cited for Microsoft April 2026 Patch Tuesday
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days
- Microsoft releases Windows 10 KB5082200 extended security update
- MSRC Security Update Guide — April 2026
- CVE-2026-32201 — SharePoint Server Spoofing Vulnerability
- CVE-2026-33825 — Microsoft Defender Antimalware Platform EoP
- CVE-2026-23666 — Windows TCP/IP Remote Code Execution
- CISA Adds CVE-2026-32201 to Known Exploited Vulnerabilities Catalog
- Zero Day Initiative — April 2026 Security Update Review
Threats related to Microsoft April 2026 Patch Tuesday
- Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited In-The-Wild, CVE-2026-33825 Defender EoP Public PoC, CVE-2026-33824 IKE RCE CVSS 9.8, CVE-2026-33827 TCP/IP Wormable RCE)
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog
- Microsoft's MDASH AI Scanning Harness Uncovers 16 Windows CVEs, Including Four Critical RCE Flaws in TCP/IP, IKEv2, Netlogon, and DNS
Detection coverage for TL-2026-0362
As of 2026-04-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0362 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.