Microsoft April 2026 Patch Tuesday — 167 Flaws, 2 Zero-Days (SharePoint Spoofing CVE-2026-32201 + Defender EoP CVE-2026-33825) — Threadlinqs Intelligence
As of 2026-05-30, Microsoft April 2026 Patch Tuesday — 167 Flaws, 2 Zero-Days (SharePoint Spoofing CVE-2026-32201 + Defender EoP CVE-2026-33825) is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0362 · Severity: CRITICAL · CVSS: 9.8 · Status: MONITORING · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Microsoft's April 2026 Patch Tuesday addresses 167 vulnerabilities including two zero-days — CVE-2026-32201, a SharePoint Server spoofing flaw actively exploited in the wild, and CVE-2026-33825, a
On April 14, 2026, Microsoft published the largest Patch Tuesday rollup of the year, remediating 167 distinct vulnerabilities across Windows, Office, SharePoint, .NET, Defender, Active Directory, Remote Desktop, Azure, Hyper-V, and supporting components. The release is notable for two zero-day entries and eight Critical-severity remote code execution bugs, several of which are wormable or trivially exploitable over the network.
Zero-Day #1 — CVE-2026-32201 (SharePoint Server Spoofing, CVSS 8.8, Actively Exploited): An improper authentication flaw in the SharePoint Server web front-end permits an unauthenticated remote attacker to craft a forged request that impersonates an authenticated user, enabling session hijack, data read, and subsequent uploads of malicious content. Microsoft's MSRC advisory and multiple incident-response vendors confirmed in-the-wild exploitation against enterprise SharePoint farms during the 30 days prior to release, with activity clustered against government, legal, and manufacturing verticals in North America and Europe. Observed post-exploitation behavior includes web-shell deployment (spinstall.aspx variants), credential harvesting from the SharePoint hive, and pivoting to the SQL backend via integrated Windows auth.
Zero-Day #2 — CVE-2026-33825 (Microsoft Defender Antimalware Platform EoP, CVSS 7.8, Publicly Disclosed): A TOCTOU race condition in the Defender update orchestrator allows a local low-privileged user to write an arbitrary file as SYSTEM via a symbolic-link hijack of the platform update staging directory. Proof-of-concept code was published to GitHub prior to Microsoft's advisory; no in-the-wild exploitation had been confirmed at release time, but the bug is trivial to weaponize and is expected to appear in commodity post-exploitation toolkits within days.
Critical RCE Highlights:
- CVE-2026-23666 — Windows TCP/IP IPv6 RCE (CVSS 9.8): Integer overflow in IPv6 fragment reassembly reachable from any adjacent network; rated wormable by MSRC.
- CVE-2026-32190 — Microsoft Word RCE (CVSS 8.4): Preview Pane attack vector; opening or previewing a crafted .docx triggers heap corruption.
- CVE-2026-33115 — .NET and Visual Studio RCE (CVSS 8.1): Unsafe deserialization in BinaryFormatter fallback path.
- CVE-2026-33114 — Remote Desktop Client RCE (CVSS 8.8): Client-side parsing flaw triggered by connecting to a rogue RDP server.
- CVE-2026-32157 — Active Directory Domain Services RCE (CVSS 9.0): Authenticated low-priv attacker writes arbitrary LDAP attributes leading to DC code execution.
- CVE-2026-33826 — Windows IKE Extensions RCE (CVSS 9.1): Malformed IKE_SA_INIT packet triggers stack overflow in IKEEXT.
- CVE-2026-33824 — Office/Outlook RCE (CVSS 8.4): Preview of a crafted email triggers OLE object handling bug.
- CVE-2026-33827 — SharePoint Server RCE (CVSS 8.8): Deserialization in workflow engine, chained by threat actors with the CVE-2026-32201 spoof.
Windows 10 Coverage: Although Windows 10 reached end-of-support in October 2025, Microsoft shipped KB5082200 as part of the Extended Security Update program, raising builds to 19045.7184 (22H2) and 19044.7184 (21H2 LTSC). The ESU is gated behind a commercial ESU license key but is broadly available to Volume Licensing and CSP customers.
Weaknesses (CWE)
CWE-287, CWE-367, CWE-502, CWE-190, CWE-121, CWE-122, CWE-59, CWE-20
Target sectors: government, legal, manufacturing, financial, healthcare, technology, education, defense
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-32201, CVE-2026-33825, CVE-2026-23666, CVE-2026-32190, CVE-2026-33115, CVE-2026-33114, CVE-2026-32157, CVE-2026-33826, CVE-2026-33824, CVE-2026-33827, T1190, T1566, T1566.001, T1203, T1204.002, T1505.003, T1068, T1574.005, T1562.001, T1555