Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited In-The-Wild, CVE-2026-33825 Defender EoP Public PoC, CVE-2026-33824 IKE RCE CVSS 9.8, CVE-2026-33827 TCP/IP Wormable RCE) — Threadlinqs Intelligence
As of 2026-05-30, Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited In-The-Wild, CVE-2026-33825 Defender EoP Public PoC, CVE-2026-33824 IKE RCE CVSS 9.8, CVE-2026-33827 TCP/IP Wormable RCE) is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0391 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Microsoft's April 2026 Patch Tuesday (released 2026-04-14) remediates 163 CVEs across 88 advisories — the second-largest Patch Tuesday on record. One zero-day (CVE-2026-32201, SharePoint Server
On 2026-04-14, Microsoft released its April 2026 Patch Tuesday security update covering 163 CVEs across 88 distinct Security Update Guide advisories. By severity, 8 are rated Critical, 154 Important, and 1 Moderate. By impact class: Elevation of Privilege dominates at 93 CVEs (57.1%), followed by 21 Information Disclosure, 20 Remote Code Execution, 13 Security Feature Bypass, 10 Denial of Service, and 9 Spoofing. Roughly 30 additional Chromium-based Microsoft Edge CVEs ship alongside.
The most urgent issue is CVE-2026-32201, a SharePoint Server spoofing vulnerability (CVSS 6.5) that Microsoft explicitly labels 'Exploited' in its disclosure, making it the month's only confirmed in-the-wild zero-day. Root cause is improper input validation in a SharePoint server-side component that permits unauthenticated cross-site-scripting–class spoofing over the network. Successful exploitation enables an unauthenticated attacker to view sensitive information and inject content into authenticated user sessions, enabling credential capture, session token theft, and pivot to on-premises Active Directory from Internet-exposed SharePoint farms. Affected versions include SharePoint Server 2016, 2019, and Subscription Edition. A sister bug, CVE-2026-20945 (CVSS 4.6, also Spoofing), affects the same attack surface but is not yet observed in exploitation.
CVE-2026-33825 is a Microsoft Defender Antimalware Platform Elevation of Privilege (CVSS 7.8). The vulnerability, credited to researchers Zen Dodd and Yuanpei XU (HUST, via Diffract), permits a local low-privileged attacker to elevate to NT AUTHORITY\SYSTEM by abusing a flaw in Defender's malware-scanning engine. A public PoC named 'BlueHammer' was published on GitHub on 2026-04-03, predating Microsoft's fix by 11 days. Remediation ships via Defender Antimalware Platform version 4.18.26030.3011 (automatic channel) rather than the monthly cumulative. Because the PoC is already public and the bug yields SYSTEM on every unpatched Windows 10/11/Server host, this class typically sees rapid integration into commodity loaders and post-exploitation toolchains.
Among Critical-rated RCEs, two exhibit wormable potential on standard enterprise deployments. CVE-2026-33824 (Windows IKE Service Extensions Remote Code Execution, CVSS 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) permits an unauthenticated remote attacker to trigger code execution through crafted IKE packets delivered to UDP ports 500 and 4500 on any host running the IKE service (commonly enabled for IPsec VPN and AlwaysOn VPN scenarios). Blocking UDP/500 and UDP/4500 at the network perimeter materially reduces external exposure but leaves insider/lateral-movement paths open. CVE-2026-33827 (Windows TCP/IP Remote Code Execution, CVSS 8.1) affects Windows hosts with both IPv6 and IPSec enabled; exploitation is gated by a race condition, partially limiting reliability but not preventing eventual worming through a flat IPv6-enabled estate. CVE-2026-33826 (Windows Active Directory Remote Code Execution, CVSS 8.0) requires an authenticated, network-adjacent attacker but yields code execution on Domain Controllers — an outcome equivalent to domain compromise.
The Office/productivity surface received three Critical RCEs: CVE-2026-33114 and CVE-2026-33115 (Microsoft Word RCE, CVSS 8.4 each) and CVE-2026-32190 (Microsoft Office RCE, CVSS 8.4). All three are triggerable via Outlook's Preview Pane when a user previews a malicious message containing an embedded or attached Office document, removing the user-click requirement that normally gates Office RCEs and raising the severity against phishing campaigns. CVE-2026-32157 (Remote Desktop Client RCE, CVSS 8.8) targets the mstsc.exe client when connecting to a malicious RDP endpoint — a well-known precursor pattern to red-team and ransomware-affiliate luring campaigns.
Secondary but notable issues include CVE-2026-27913 (Windows BitLocker Secure Boot bypass, CVSS 7.7, 'Exploitation More Likely'), whic
Weaknesses (CWE)
CWE-79, CWE-20, CWE-269, CWE-362, CWE-787, CWE-190, CWE-284, CWE-287, CWE-400, CWE-502
Target sectors: government, financial, healthcare, technology, energy, manufacturing, defense, education, legal, telecommunications, retail, transportation
Target regions: North America, Europe, Asia-Pacific, Latin America, Middle East, Africa, Global
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-32201, CVE-2026-20945, CVE-2026-33825, CVE-2026-33824, CVE-2026-33827, CVE-2026-33826, CVE-2026-32157, CVE-2026-33114, CVE-2026-33115, CVE-2026-32190, T1595, T1592, T1587, T1588, T1190, T1189, T1566, T1566, T1203, T1204