Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days
15 mins read

Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days

Today is Microsoft’s April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.

This Patch Tuesday also addresses eight “Critical” vulnerabilities, 7 of which are remote code execution flaws and the other is a denial of service flaw.

The number of bugs in each vulnerability category is listed below:

  • 93 Elevation of Privilege Vulnerabilities
  • 13 Security Feature Bypass Vulnerabilities
  • 20 Remote Code Execution Vulnerabilities
  • 21 Information Disclosure Vulnerabilities
  • 10 Denial of Service Vulnerabilities
  • 9 Spoofing Vulnerabilities

When GeekFeed reports on Patch Tuesday security updates, we only count those released by Microsoft today.

Therefore, the number of flaws does not include Mariner, Azure, and Bing flaws that were fixed by Microsoft earlier this month. There were also 80 Microsoft Edge/Chromium flaws that were fixed by Google.

To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5083769 & KB5082052 cumulative updates and the Windows 10 KB5082200 extended security update.

2 zero-days and Microsoft Office flaws

This month’s Patch Tuesday fixes two zero-day vulnerabilities, with one publicly disclosed and the other actively exploited in attacks.

Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.

The actively exploited zero-day flaw is:

CVE-2026-32201 – Microsoft SharePoint Server Spoofing Vulnerability

Microsoft has patched a Microsoft SharePoint Server Spoofing Vulnerability that was exploited in attacks.

“Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network,” explains Microsoft.

“An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality), make changes to disclosed information (Integrity), but cannot limit access to the resource (Availability),” continued Microsoft.

Microsoft has not disclosed how this vulnerability was exploited in attacks or who disclosed it.

The publicly disclosed zero-day is:

CVE-2026-33825 – Microsoft Defender Elevation of Privilege Vulnerability

Microsoft has patched a Microsoft Defender privilege elevation flaw that gives SYSTEM privileges.

The company has addressed the flaw in the Microsoft Defender Antimalware Platform update version 4.18.26030.3011, which will automatically be downloaded to systems.

Windows users can manually install it by going to Windows Security > Virus & threat protection > Protection Updates, then clicking Check for updates.

Microsoft has credited Zen Dodd and Yuanpei XU (HUST) with Diffract with discovering this flaw.

Microsoft has also fixed multiple remote code execution bugs in Microsoft Office (Word and Excel) that can be executed via the preview pane or by opening malicious documents.

Therefore, users should prioritize updating Microsoft Office as soon as possible, especially if they commonly receive attachments.

The April 2026 Patch Tuesday Security Updates

Below is the complete list of resolved vulnerabilities in the April 2026 Patch Tuesday updates.

To access the full description of each vulnerability and the systems it affects, you can view the full report here.

TagCVE IDCVE TitleSeverity
.NETCVE-2026-26171.NET Denial of Service VulnerabilityImportant
.NETCVE-2026-32178.NET Spoofing VulnerabilityImportant
.NET and Visual StudioCVE-2026-32203.NET and Visual Studio Denial of Service VulnerabilityImportant
.NET FrameworkCVE-2026-23666.NET Framework Denial of Service VulnerabilityCritical
.NET FrameworkCVE-2026-32226.NET Framework Denial of Service VulnerabilityImportant
.NET, .NET Framework, Visual StudioCVE-2026-33116.NET, .NET Framework, and Visual Studio Denial of Service VulnerabilityImportant
Applocker Filter Driver (applockerfltr.sys)CVE-2026-25184Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege VulnerabilityImportant
Azure Logic AppsCVE-2026-32171Azure Logic Apps Elevation of Privilege VulnerabilityImportant
Azure Monitor AgentCVE-2026-32192Azure Monitor Agent Elevation of Privilege VulnerabilityImportant
Azure Monitor AgentCVE-2026-32168Azure Monitor Agent Elevation of Privilege VulnerabilityImportant
Desktop Window ManagerCVE-2026-27924Desktop Window Manager Elevation of Privilege VulnerabilityImportant
Desktop Window ManagerCVE-2026-32154Desktop Window Manager Elevation of Privilege VulnerabilityImportant
Desktop Window ManagerCVE-2026-32152Desktop Window Manager Elevation of Privilege VulnerabilityImportant
Desktop Window ManagerCVE-2026-27923Desktop Window Manager Elevation of Privilege VulnerabilityImportant
Desktop Window ManagerCVE-2026-32155Desktop Window Manager Elevation of Privilege VulnerabilityImportant
Function Discovery Service (fdwsd.dll)CVE-2026-32087Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege VulnerabilityImportant
Function Discovery Service (fdwsd.dll)CVE-2026-32086Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege VulnerabilityImportant
Function Discovery Service (fdwsd.dll)CVE-2026-32150Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege VulnerabilityImportant
Function Discovery Service (fdwsd.dll)CVE-2026-32093Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege VulnerabilityImportant
GitHub Copilot and Visual Studio CodeCVE-2026-23653GitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityImportant
GitHub Repo: Git for WindowsCVE-2026-32631GitHub: CVE-2026-32631 ‘git clone’ from manipulated repositories can leak NTLM hashesImportant
Input-Output Memory Management Unit (IOMMU)CVE-2023-20585AMD: CVE-2023-20585 IOMMU Write Buffer VulnerabilityImportant
Microsoft Brokering File SystemCVE-2026-32091Microsoft Brokering File System Elevation of Privilege VulnerabilityImportant
Microsoft Brokering File SystemCVE-2026-32219Microsoft Brokering File System Elevation of Privilege VulnerabilityImportant
Microsoft Brokering File SystemCVE-2026-26181Microsoft Brokering File System Elevation of Privilege VulnerabilityImportant
Microsoft DefenderCVE-2026-33825Microsoft Defender Elevation of Privilege VulnerabilityImportant
Microsoft Dynamics 365 (on-premises)CVE-2026-33103Microsoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2026-32221Windows Graphics Component Remote Code Execution VulnerabilityImportant
Microsoft High Performance Compute Pack (HPC)CVE-2026-32184Microsoft High Performance Compute (HPC) Pack Elevation of Privilege VulnerabilityImportant
Microsoft Management ConsoleCVE-2026-27914Microsoft Management Console Elevation of Privilege VulnerabilityImportant
Microsoft OfficeCVE-2026-32190Microsoft Office Remote Code Execution VulnerabilityCritical
Microsoft Office ExcelCVE-2026-32199Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2026-32198Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2026-32197Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office ExcelCVE-2026-32188Microsoft Excel Information Disclosure VulnerabilityImportant
Microsoft Office ExcelCVE-2026-32189Microsoft Excel Remote Code Execution VulnerabilityImportant
Microsoft Office PowerPointCVE-2026-32200Microsoft PowerPoint Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2026-32201Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft Office SharePointCVE-2026-20945Microsoft SharePoint Server Spoofing VulnerabilityImportant
Microsoft Office WordCVE-2026-23657Microsoft Word Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2026-33115Microsoft Word Remote Code Execution VulnerabilityCritical
Microsoft Office WordCVE-2026-33114Microsoft Word Remote Code Execution VulnerabilityCritical
Microsoft Office WordCVE-2026-33095Microsoft Word Remote Code Execution VulnerabilityImportant
Microsoft Office WordCVE-2026-33822Microsoft Word Information Disclosure VulnerabilityImportant
Microsoft Power AppsCVE-2026-26149Microsoft Power Apps Security Feature BypassImportant
Microsoft PowerShellCVE-2026-26143Microsoft PowerShell Security Feature Bypass VulnerabilityImportant
Microsoft PowerShellCVE-2026-26170PowerShell Elevation of Privilege VulnerabilityImportant
Microsoft WindowsCVE-2026-32181Connected User Experiences and Telemetry Service Denial of Service VulnerabilityImportant
Microsoft Windows Search ComponentCVE-2026-27909Windows Search Service Elevation of Privilege VulnerabilityImportant
Microsoft Windows SpeechCVE-2026-32153Windows Speech Runtime Elevation of Privilege VulnerabilityImportant
Node.jsCVE-2026-21637HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error HandlersModerate
Remote Desktop ClientCVE-2026-32157Remote Desktop Client Remote Code Execution VulnerabilityCritical
Role: Windows Hyper-VCVE-2026-32149Windows Hyper-V Remote Code Execution VulnerabilityImportant
Role: Windows Hyper-VCVE-2026-26156Windows Hyper-V Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2026-33120Microsoft SQL Server Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2026-32176SQL Server Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2026-32167SQL Server Elevation of Privilege VulnerabilityImportant
Universal Plug and Play (upnp.dll)CVE-2026-32212Universal Plug and Play (upnp.dll) Information Disclosure VulnerabilityImportant
Universal Plug and Play (upnp.dll)CVE-2026-32214Universal Plug and Play (upnp.dll) Information Disclosure VulnerabilityImportant
Windows Active DirectoryCVE-2026-32072Active Directory Spoofing VulnerabilityImportant
Windows Active DirectoryCVE-2026-33826Windows Active Directory Remote Code Execution VulnerabilityCritical
Windows Admin CenterCVE-2026-32196Windows Admin Center Spoofing VulnerabilityImportant
Windows Advanced Rasterization PlatformCVE-2026-26178Windows Advanced Rasterization Platform Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-27922Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-26177Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-32073Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-26168Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-26182Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-26173Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-33100Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Ancillary Function Driver for WinSockCVE-2026-33099Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityImportant
Windows Biometric ServiceCVE-2026-32088Windows Biometric Service Security Feature Bypass VulnerabilityImportant
Windows BitLockerCVE-2026-27913Windows BitLocker Security Feature Bypass VulnerabilityImportant
Windows Boot LoaderCVE-2026-0390UEFI Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Boot ManagerCVE-2026-26175Windows Boot Manager Security Feature Bypass VulnerabilityImportant
Windows Client Side Caching driver (csc.sys)CVE-2026-26176Windows Client Side Caching driver (csc.sys) Elevation of Privilege VulnerabilityImportant
Windows Cloud Files Mini Filter DriverCVE-2026-27926Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityImportant
Windows COMCVE-2026-32162Windows COM Elevation of Privilege VulnerabilityImportant
Windows COMCVE-2026-20806Windows COM Server Information Disclosure VulnerabilityImportant
Windows Common Log File System DriverCVE-2026-32070Windows Common Log File System Driver Elevation of Privilege VulnerabilityImportant
Windows Container Isolation FS Filter DriverCVE-2026-33098Windows Container Isolation FS Filter Driver Elevation of Privilege VulnerabilityImportant
Windows Cryptographic ServicesCVE-2026-26152Microsoft Cryptographic Services Elevation of Privilege VulnerabilityImportant
Windows Encrypting File System (EFS)CVE-2026-26153Windows Encrypted File System (EFS) Elevation of Privilege VulnerabilityImportant
Windows File ExplorerCVE-2026-32084Windows Print Spooler Information Disclosure VulnerabilityImportant
Windows File ExplorerCVE-2026-32079Web Account Manager Information Disclosure VulnerabilityImportant
Windows File ExplorerCVE-2026-32081Package Catalog Information Disclosure VulnerabilityImportant
Windows GDICVE-2026-27931Windows GDI Information Disclosure VulnerabilityImportant
Windows GDICVE-2026-27930Windows GDI Information Disclosure VulnerabilityImportant
Windows HelloCVE-2026-27928Windows Hello Security Feature Bypass VulnerabilityImportant
Windows HelloCVE-2026-27906Windows Hello Security Feature Bypass VulnerabilityImportant
Windows HTTP.sysCVE-2026-33096HTTP.sys Denial of Service VulnerabilityImportant
Windows IKE ExtensionCVE-2026-33824Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution VulnerabilityCritical
Windows InstallerCVE-2026-27910Windows Installer Elevation of Privilege VulnerabilityImportant
Windows KerberosCVE-2026-27912Windows Kerberos Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-32215Windows Kernel Information Disclosure VulnerabilityImportant
Windows KernelCVE-2026-32218Windows Kernel Information Disclosure VulnerabilityImportant
Windows KernelCVE-2026-26179Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-32217Windows Kernel Information Disclosure VulnerabilityImportant
Windows KernelCVE-2026-26163Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-32195Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows KernelCVE-2026-26180Windows Kernel Elevation of Privilege VulnerabilityImportant
Windows Kernel MemoryCVE-2026-26169Windows Kernel Memory Information Disclosure VulnerabilityImportant
Windows Local Security Authority Subsystem Service (LSASS)CVE-2026-26155Microsoft Local Security Authority Subsystem Service Information Disclosure VulnerabilityImportant
Windows Local Security Authority Subsystem Service (LSASS)CVE-2026-32071Windows Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityImportant
Windows LUAFVCVE-2026-27929Windows LUA File Virtualization Filter Driver Elevation of Privilege VulnerabilityImportant
Windows Management ServicesCVE-2026-20930Windows Management Services Elevation of Privilege VulnerabilityImportant
Windows OLECVE-2026-26162Windows OLE Elevation of Privilege VulnerabilityImportant
Windows Print Spooler ComponentsCVE-2026-33101Windows Print Spooler Elevation of Privilege VulnerabilityImportant
Windows Projected File SystemCVE-2026-26184Windows Projected File System Elevation of Privilege VulnerabilityImportant
Windows Projected File SystemCVE-2026-32078Windows Projected File System Elevation of Privilege VulnerabilityImportant
Windows Projected File SystemCVE-2026-32074Windows Projected File System Elevation of Privilege VulnerabilityImportant
Windows Projected File SystemCVE-2026-32069Windows Projected File System Elevation of Privilege VulnerabilityImportant
Windows Projected File SystemCVE-2026-27927Windows Projected File System Elevation of Privilege VulnerabilityImportant
Windows Push NotificationsCVE-2026-32159Windows Push Notifications Elevation of Privilege VulnerabilityImportant
Windows Push NotificationsCVE-2026-32160Windows Push Notifications Elevation of Privilege VulnerabilityImportant
Windows Push NotificationsCVE-2026-26167Windows Push Notifications Elevation of Privilege VulnerabilityImportant
Windows Push NotificationsCVE-2026-26172Windows Push Notifications Elevation of Privilege VulnerabilityImportant
Windows Push NotificationsCVE-2026-32158Windows Push Notifications Elevation of Privilege VulnerabilityImportant
Windows Recovery Environment AgentCVE-2026-20928Windows Recovery Environment Security Feature Bypass VulnerabilityImportant
Windows Redirected Drive BufferingCVE-2026-32216Windows Redirected Drive Buffering System Denial of Service VulnerabilityImportant
Windows Remote DesktopCVE-2026-26151Remote Desktop Spoofing VulnerabilityImportant
Windows Remote Desktop Licensing ServiceCVE-2026-26159Remote Desktop Licensing Service Elevation of Privilege VulnerabilityImportant
Windows Remote Desktop Licensing ServiceCVE-2026-26160Remote Desktop Licensing Service Elevation of Privilege VulnerabilityImportant
Windows Remote Procedure CallCVE-2026-32085Remote Procedure Call Information Disclosure VulnerabilityImportant
Windows RPC APICVE-2026-26183Remote Access Management service/API (RPC server) Elevation of Privilege VulnerabilityImportant
Windows Secure BootCVE-2026-25250MITRE: CVE-2026-25250 Secure Boot disable Eazy FixImportant
Windows Sensor Data ServiceCVE-2026-26161Windows Sensor Data Service Elevation of Privilege VulnerabilityImportant
Windows Server Update ServiceCVE-2026-32224Windows Server Update Service (WSUS) Elevation of Privilege VulnerabilityImportant
Windows Server Update ServiceCVE-2026-26174Windows Server Update Service (WSUS) Elevation of Privilege VulnerabilityImportant
Windows Server Update ServiceCVE-2026-26154Windows Server Update Service (WSUS) Tampering VulnerabilityImportant
Windows ShellCVE-2026-27918Windows Shell Elevation of Privilege VulnerabilityImportant
Windows ShellCVE-2026-26165Windows Shell Elevation of Privilege VulnerabilityImportant
Windows ShellCVE-2026-26166Windows Shell Elevation of Privilege VulnerabilityImportant
Windows ShellCVE-2026-32225Windows Shell Security Feature Bypass VulnerabilityImportant
Windows ShellCVE-2026-32151Windows Shell Information Disclosure VulnerabilityImportant
Windows ShellCVE-2026-32202Windows Shell Spoofing VulnerabilityImportant
Windows Snipping ToolCVE-2026-32183Windows Snipping Tool Remote Code Execution VulnerabilityImportant
Windows Snipping ToolCVE-2026-33829Windows Snipping Tool Spoofing VulnerabilityModerate
Windows Speech Brokered ApiCVE-2026-32089Windows Speech Brokered Api Elevation of Privilege VulnerabilityImportant
Windows Speech Brokered ApiCVE-2026-32090Windows Speech Brokered Api Elevation of Privilege VulnerabilityImportant
Windows SSDP ServiceCVE-2026-32083Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege VulnerabilityImportant
Windows SSDP ServiceCVE-2026-32082Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege VulnerabilityImportant
Windows SSDP ServiceCVE-2026-32068Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege VulnerabilityImportant
Windows Storage Spaces ControllerCVE-2026-32076Windows Storage Spaces Controller Elevation of Privilege VulnerabilityImportant
Windows Storage Spaces ControllerCVE-2026-27907Windows Storage Spaces Controller Elevation of Privilege VulnerabilityImportant
Windows TCP/IPCVE-2026-27921Windows TDI Translation Driver (tdx.sys) Elevation of Privilege VulnerabilityImportant
Windows TCP/IPCVE-2026-33827Windows TCP/IP Remote Code Execution VulnerabilityCritical
Windows TDI Translation Driver (tdx.sys)CVE-2026-27908Windows TDI Translation Driver (tdx.sys) Elevation of Privilege VulnerabilityImportant
Windows Universal Plug and Play (UPnP) Device HostCVE-2026-27916Windows UPnP Device Host Elevation of Privilege VulnerabilityImportant
Windows Universal Plug and Play (UPnP) Device HostCVE-2026-32156Windows UPnP Device Host Remote Code Execution VulnerabilityImportant
Windows Universal Plug and Play (UPnP) Device HostCVE-2026-32077Windows UPnP Device Host Elevation of Privilege VulnerabilityImportant
Windows Universal Plug and Play (UPnP) Device HostCVE-2026-27915Windows UPnP Device Host Elevation of Privilege VulnerabilityImportant
Windows Universal Plug and Play (UPnP) Device HostCVE-2026-27919Windows UPnP Device Host Elevation of Privilege VulnerabilityImportant
Windows Universal Plug and Play (UPnP) Device HostCVE-2026-27925Windows UPnP Device Host Information Disclosure VulnerabilityImportant
Windows Universal Plug and Play (UPnP) Device HostCVE-2026-32075Windows UPnP Device Host Elevation of Privilege VulnerabilityImportant
Windows Universal Plug and Play (UPnP) Device HostCVE-2026-27920Windows UPnP Device Host Elevation of Privilege VulnerabilityImportant
Windows USB Print DriverCVE-2026-32223Windows USB Printing Stack (usbprint.sys) Elevation of Privilege VulnerabilityImportant
Windows User Interface CoreCVE-2026-32165Windows User Interface Core Elevation of Privilege VulnerabilityImportant
Windows User Interface CoreCVE-2026-32164Windows User Interface Core Elevation of Privilege VulnerabilityImportant
Windows User Interface CoreCVE-2026-27911Windows User Interface Core Elevation of Privilege VulnerabilityImportant
Windows User Interface CoreCVE-2026-32163Windows User Interface Core Elevation of Privilege VulnerabilityImportant
Windows Virtualization-Based Security (VBS) EnclaveCVE-2026-23670Windows Virtualization-Based Security (VBS) Security Feature Bypass VulnerabilityImportant
Windows Virtualization-Based Security (VBS) EnclaveCVE-2026-32220UEFI Secure Boot Security Feature Bypass VulnerabilityImportant
Windows WalletServiceCVE-2026-32080Windows WalletService Elevation of Privilege VulnerabilityImportant
Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys)CVE-2026-27917Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege VulnerabilityImportant
Windows Win32K – GRFXCVE-2026-33104Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K – ICOMPCVE-2026-32222Windows Win32k Elevation of Privilege VulnerabilityImportant

Leave a Reply

Your email address will not be published. Required fields are marked *