ai-security EN

Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)

Microsoft Patch Tuesday April 2026.

Published
2026-04-14. Last Updated
2026-04-14 17:46:09 UTC

by Johannes Ullrich (Version: 1)

0 comment(s)

This month’s Microsoft Patch Tuesday looks like a record one, but let’s look at it a bit closer to understand what is happening

The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier. This leaves 165 vulnerabilities that are not Edge-related. Of these, 8 are rated critical, and 154 are important. One vulnerability has already been exploited, and another was made public before today but has not yet been seen in the wild.

Noteworthy Vulnerabilities:

CVE-2026-33827 (Windows TCP/IP Remote Code Execution Vulnerability): As a packet nerd, I love these types of vulnerabilities. Need to know more to really figure out the impact. Microsoft describes this as a race condition, allowing attackers to execute arbitrary code over the network. Exploitation is likely tricky, but never underestimate the creativity of an AI aided attacker.

CVE-2026-33825 (Microsoft Defender Elevation of Privilege Vulnerability): This vulnerability has already been disclosed.

CVE-2026-32201 (Microsoft SharePoint Server Spoofing Vulnerability): Two similar SharePoint server spoofing vulnerabilities were patched this month. Both are rated important, and this particular one is already being exploited.

CVE-2026-33826 (Windows Active Directory Remote Code Execution Vulnerability): CVSS score of “only” 8.0, but critical according to Microsoft.

CVE-2026-32190 (Microsoft Office Remote Code Execution Vulnerability): Standard fair for every monthly patch Tuesday. These are often the more worrisome vulnerabilities. Two additional critical RCE vulnerabilities affect Word (CVE-2026-33114, CVE-2026-33115).

CVE-2026-32157 (Remote Desktop Client Remote Code Execution Vulnerability): Typically, these vulnerabilities require a user to connect to a malicious RDP server, but connections may be initiated by clicking on an “rdp:” link.

CVE-2026-33824 (Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability): IKE, part of IPSEC, is usually not enabled by default. It isn’t clear yet what the exact exploitation requirements are (will update once MSFT’s page responds again)

CVE-2026-23666 (.NET Framework Denial of Service Vulnerability): Just a denial of service. Not sure why this deserved “critical”.

Description
CVEDisclosedExploitedExploitability (old versions)current versionSeverityCVSS Base (AVG)CVSS Temporal (AVG)
.NET Denial of Service Vulnerability
CVE-2026-26171NoNo--Important7.56.5
.NET Framework Denial of Service Vulnerability
CVE-2026-32226NoNo--Important5.95.2
CVE-2026-23666NoNo--Critical7.56.7
.NET Spoofing Vulnerability
CVE-2026-32178NoNo--Important7.56.5
.NET and Visual Studio Denial of Service Vulnerability
CVE-2026-32203NoNo--Important7.56.5
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2026-33116NoNo--Important7.56.5
Active Directory Spoofing Vulnerability
CVE-2026-32072NoNo--Important6.25.4
Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability
CVE-2026-25184NoNo--Important7.06.1
Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-32171NoNo--Important8.87.7
Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2026-32168NoNo--Important7.86.8
CVE-2026-32192NoNo--Important7.86.8
Chromium: CVE-2026-5272 Heap buffer overflow in GPU
CVE-2026-5272NoNo---
Chromium: CVE-2026-5273 Use after free in CSS
CVE-2026-5273NoNo---
Chromium: CVE-2026-5274 Integer overflow in Codecs
CVE-2026-5274NoNo---
Chromium: CVE-2026-5275 Heap buffer overflow in ANGLE
CVE-2026-5275NoNo---
Chromium: CVE-2026-5276 Insufficient policy enforcement in WebUSB
CVE-2026-5276NoNo---
Chromium: CVE-2026-5277 Integer overflow in ANGLE
CVE-2026-5277NoNo---
Chromium: CVE-2026-5279 Object corruption in V8
CVE-2026-5279NoNo---
Chromium: CVE-2026-5280 Use after free in WebCodecs
CVE-2026-5280NoNo---
Chromium: CVE-2026-5281 Use after free in Dawn
CVE-2026-5281NoNo---
Chromium: CVE-2026-5283 Inappropriate implementation in ANGLE
CVE-2026-5283NoNo---
Chromium: CVE-2026-5284 Use after free in Dawn
CVE-2026-5284NoNo---
Chromium: CVE-2026-5285 Use after free in WebGL
CVE-2026-5285NoNo---
Chromium: CVE-2026-5286 Use after free in Dawn
CVE-2026-5286NoNo---
Chromium: CVE-2026-5287 Use after free in PDF
CVE-2026-5287NoNo---
Chromium: CVE-2026-5289 Use after free in Navigation
CVE-2026-5289NoNo---
Chromium: CVE-2026-5290 Use after free in Compositing
CVE-2026-5290NoNo---
Chromium: CVE-2026-5291 Inappropriate implementation in WebGL
CVE-2026-5291NoNo---
Chromium: CVE-2026-5292 Out of bounds read in WebCodecs
CVE-2026-5292NoNo---
Chromium: CVE-2026-5858 Heap buffer overflow in WebML
CVE-2026-5858NoNo---
Chromium: CVE-2026-5859 Integer overflow in WebML
CVE-2026-5859NoNo---
Chromium: CVE-2026-5860 Use after free in WebRTC
CVE-2026-5860NoNo---
Chromium: CVE-2026-5861 Use after free in V8
CVE-2026-5861NoNo---
Chromium: CVE-2026-5862 Inappropriate implementation in V8
CVE-2026-5862NoNo---
Chromium: CVE-2026-5863 Inappropriate implementation in V8
CVE-2026-5863NoNo---
Chromium: CVE-2026-5864 Heap buffer overflow in WebAudio
CVE-2026-5864NoNo---
Chromium: CVE-2026-5865 Type Confusion in V8
CVE-2026-5865NoNo---
Chromium: CVE-2026-5866 Use after free in Media
CVE-2026-5866NoNo---
Chromium: CVE-2026-5867 Heap buffer overflow in WebML
CVE-2026-5867NoNo---
Chromium: CVE-2026-5868 Heap buffer overflow in ANGLE
CVE-2026-5868NoNo---
Chromium: CVE-2026-5869 Heap buffer overflow in WebML
CVE-2026-5869NoNo---
Chromium: CVE-2026-5870 Integer overflow in Skia
CVE-2026-5870NoNo---
Chromium: CVE-2026-5871 Type Confusion in V8
CVE-2026-5871NoNo---
Chromium: CVE-2026-5872 Use after free in Blink
CVE-2026-5872NoNo---
Chromium: CVE-2026-5873 Out of bounds read and write in V8
CVE-2026-5873NoNo---
Chromium: CVE-2026-5874 Use after free in PrivateAI
CVE-2026-5874NoNo---
Chromium: CVE-2026-5875 Policy bypass in Blink
CVE-2026-5875NoNo---
Chromium: CVE-2026-5876 Side-channel information leakage in Navigation
CVE-2026-5876NoNo---
Chromium: CVE-2026-5877 Use after free in Navigation
CVE-2026-5877NoNo---
Chromium: CVE-2026-5878 Incorrect security UI in Blink
CVE-2026-5878NoNo---
Chromium: CVE-2026-5879 Insufficient validation of untrusted input in ANGLE
CVE-2026-5879NoNo---
Chromium: CVE-2026-5880 Incorrect security UI in browser UI
CVE-2026-5880NoNo---
Chromium: CVE-2026-5881 Policy bypass in LocalNetworkAccess
CVE-2026-5881NoNo---
Chromium: CVE-2026-5882 Incorrect security UI in Fullscreen
CVE-2026-5882NoNo---
Chromium: CVE-2026-5883 Use after free in Media
CVE-2026-5883NoNo---
Chromium: CVE-2026-5884 Insufficient validation of untrusted input in Media
CVE-2026-5884NoNo---
Chromium: CVE-2026-5885 Insufficient validation of untrusted input in WebML
CVE-2026-5885NoNo---
Chromium: CVE-2026-5886 Out of bounds read in WebAudio
CVE-2026-5886NoNo---
Chromium: CVE-2026-5887 Insufficient validation of untrusted input in Downloads
CVE-2026-5887NoNo---
Chromium: CVE-2026-5888 Uninitialized Use in WebCodecs
CVE-2026-5888NoNo---
Chromium: CVE-2026-5889 Cryptographic Flaw in PDFium
CVE-2026-5889NoNo---
Chromium: CVE-2026-5890 Race in WebCodecs
CVE-2026-5890NoNo---
Chromium: CVE-2026-5891 Insufficient policy enforcement in browser UI
CVE-2026-5891NoNo---
Chromium: CVE-2026-5892 Insufficient policy enforcement in PWAs
CVE-2026-5892NoNo---
Chromium: CVE-2026-5893 Race in V8
CVE-2026-5893NoNo---
Chromium: CVE-2026-5894 Inappropriate implementation in PDF
CVE-2026-5894NoNo---
Chromium: CVE-2026-5895 Incorrect security UI in Omnibox
CVE-2026-5895NoNo---
Chromium: CVE-2026-5896 Policy bypass in Audio
CVE-2026-5896NoNo---
Chromium: CVE-2026-5897 Incorrect security UI in Downloads
CVE-2026-5897NoNo---
Chromium: CVE-2026-5898 Incorrect security UI in Omnibox
CVE-2026-5898NoNo---
Chromium: CVE-2026-5899 Incorrect security UI in History Navigation
CVE-2026-5899NoNo---
Chromium: CVE-2026-5900 Policy bypass in Downloads
CVE-2026-5900NoNo---
Chromium: CVE-2026-5901 Policy bypass in DevTools
CVE-2026-5901NoNo---
Chromium: CVE-2026-5902 Race in Media
CVE-2026-5902NoNo---
Chromium: CVE-2026-5903 Policy bypass in IFrameSandbox
CVE-2026-5903NoNo---
Chromium: CVE-2026-5904 Use after free in V8
CVE-2026-5904NoNo---
Chromium: CVE-2026-5905 Incorrect security UI in Permissions
CVE-2026-5905NoNo---
Chromium: CVE-2026-5906 Incorrect security UI in Omnibox
CVE-2026-5906NoNo---
Chromium: CVE-2026-5907 Insufficient data validation in Media
CVE-2026-5907NoNo---
Chromium: CVE-2026-5908 Integer overflow in Media
CVE-2026-5908NoNo---
Chromium: CVE-2026-5909 Integer overflow in Media
CVE-2026-5909NoNo---
Chromium: CVE-2026-5910 Integer overflow in Media
CVE-2026-5910NoNo---
Chromium: CVE-2026-5911 Policy bypass in ServiceWorkers
CVE-2026-5911NoNo---
Chromium: CVE-2026-5912 Integer overflow in WebRTC
CVE-2026-5912NoNo---
Chromium: CVE-2026-5913 Out of bounds read in Blink
CVE-2026-5913NoNo---
Chromium: CVE-2026-5914 Type Confusion in CSS
CVE-2026-5914NoNo---
Chromium: CVE-2026-5915 Insufficient validation of untrusted input in WebML
CVE-2026-5915NoNo---
Chromium: CVE-2026-5918 Inappropriate implementation in Navigation
CVE-2026-5918NoNo---
Chromium: CVE-2026-5919 Insufficient validation of untrusted input in WebSockets
CVE-2026-5919NoNo---
Connected User Experiences and Telemetry Service Denial of Service Vulnerability
CVE-2026-32181NoNo--Important5.54.8
Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-27924NoNo--Important7.86.8
CVE-2026-32152NoNo--Important7.86.8
CVE-2026-32154NoNo--Important7.86.8
CVE-2026-27923NoNo--Important7.86.8
CVE-2026-32155NoNo--Important7.86.8
GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVE-2026-23653NoNo--Important5.75.0
HTTP.sys Denial of Service Vulnerability
CVE-2026-33096NoNo--Important7.56.5
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-26181NoNo--Important7.86.8
CVE-2026-32219NoNo--Important7.06.1
CVE-2026-32091NoNo--Important8.47.3
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2026-26152NoNo--Important7.06.1
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2026-33825YesNo--Important7.87.0
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2026-33103NoNo--Important5.54.8
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-33118NoNo--Low4.33.8
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-33119NoNo--Moderate5.44.7
Microsoft Excel Information Disclosure Vulnerability
CVE-2026-32188NoNo--Important7.16.2
Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32189NoNo--Important7.86.8
CVE-2026-32197NoNo--Important7.86.8
CVE-2026-32198NoNo--Important7.86.8
CVE-2026-32199NoNo--Important7.86.8
Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability
CVE-2026-32184NoNo--Important7.86.8
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
CVE-2026-26155NoNo--Important6.55.7
Microsoft Management Console Elevation of Privilege Vulnerability
CVE-2026-27914NoNo--Important7.86.8
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-32190NoNo--Critical8.47.3
Microsoft Power Apps Security Feature Bypass
CVE-2026-26149NoNo--Important9.07.9
Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-32200NoNo--Important7.86.8
Microsoft PowerShell Security Feature Bypass Vulnerability
CVE-2026-26143NoNo--Important7.86.8
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-33120NoNo--Important8.87.7
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-20945NoNo--Important4.64.0
CVE-2026-32201NoYes--Important6.56.0
Microsoft Word Information Disclosure Vulnerability
CVE-2026-33822NoNo--Important6.15.3
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-33095NoNo--Important7.86.8
CVE-2026-23657NoNo--Important7.86.8
CVE-2026-33114NoNo--Critical8.47.3
CVE-2026-33115NoNo--Critical8.47.3
Package Catalog Information Disclosure Vulnerability
CVE-2026-32081NoNo--Important5.54.8
PowerShell Elevation of Privilege Vulnerability
CVE-2026-26170NoNo--Important7.86.8
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
CVE-2026-26183NoNo--Important7.86.8
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-32157NoNo--Critical8.87.7
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVE-2026-26160NoNo--Important7.86.8
CVE-2026-26159NoNo--Important7.86.8
Remote Desktop Spoofing Vulnerability
CVE-2026-26151NoNo--Important7.16.2
Remote Procedure Call Information Disclosure Vulnerability
CVE-2026-32085NoNo--Important5.54.8
SQL Server Elevation of Privilege Vulnerability
CVE-2026-32167NoNo--Important6.75.8
CVE-2026-32176NoNo--Important6.75.8
UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-0390NoNo--Important6.75.8
CVE-2026-32220NoNo--Important4.43.9
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVE-2026-32212NoNo--Important5.54.8
CVE-2026-32214NoNo--Important5.54.8
Web Account Manager Information Disclosure Vulnerability
CVE-2026-32079NoNo--Important5.54.8
Win32k Elevation of Privilege Vulnerability
CVE-2026-33104NoNo--Important7.06.1
Windows Active Directory Remote Code Execution Vulnerability
CVE-2026-33826NoNo--Critical8.07.0
Windows Admin Center Spoofing Vulnerability
CVE-2026-32196NoNo--Important6.15.3
Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability
CVE-2026-26178NoNo--Important8.87.7
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-32073NoNo--Important7.06.1
CVE-2026-26168NoNo--Important7.86.8
CVE-2026-26173NoNo--Important7.06.1
CVE-2026-26177NoNo--Important7.06.1
CVE-2026-26182NoNo--Important7.06.1
CVE-2026-27922NoNo--Important7.06.1
CVE-2026-33099NoNo--Important7.06.1
CVE-2026-33100NoNo--Important7.06.1
Windows Biometric Service Security Feature Bypass Vulnerability
CVE-2026-32088NoNo--Important6.15.3
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-27913NoNo--Important7.76.7
Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-26175NoNo--Important4.64.0
Windows COM Elevation of Privilege Vulnerability
CVE-2026-32162NoNo--Important8.47.3
Windows COM Server Information Disclosure Vulnerability
CVE-2026-20806NoNo--Important5.54.8
Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability
CVE-2026-26176NoNo--Important7.86.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-27926NoNo--Important7.06.1
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-32070NoNo--Important7.06.1
Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
CVE-2026-33098NoNo--Important7.86.8
Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability
CVE-2026-26153NoNo--Important7.86.8
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32087NoNo--Important7.06.1
CVE-2026-32093NoNo--Important7.06.1
CVE-2026-32086NoNo--Important7.06.1
CVE-2026-32150NoNo--Important7.06.1
Windows GDI Information Disclosure Vulnerability
CVE-2026-27931NoNo--Important5.54.8
CVE-2026-27930NoNo--Important5.54.8
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-32221NoNo--Important8.47.3
Windows Hello Security Feature Bypass Vulnerability
CVE-2026-27906NoNo--Important4.43.9
CVE-2026-27928NoNo--Important8.77.6
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-26156NoNo--Important7.86.8
CVE-2026-32149NoNo--Important7.36.4
Windows Installer Elevation of Privilege Vulnerability
CVE-2026-27910NoNo--Important7.86.8
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
CVE-2026-33824NoNo--Critical9.88.5
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-27912NoNo--Important8.07.0
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26179NoNo--Important7.86.8
CVE-2026-26180NoNo--Important7.86.8
CVE-2026-32195NoNo--Important7.06.1
CVE-2026-26163NoNo--Important7.86.8
Windows Kernel Information Disclosure Vulnerability
CVE-2026-32215NoNo--Important5.54.8
CVE-2026-32217NoNo--Important5.54.8
CVE-2026-32218NoNo--Important5.54.8
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2026-26169NoNo--Important6.15.3
Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
CVE-2026-27929NoNo--Important7.06.1
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-32071NoNo--Important7.56.5
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20930NoNo--Important7.86.8
Windows OLE Elevation of Privilege Vulnerability
CVE-2026-26162NoNo--Important7.86.8
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2026-33101NoNo--Important7.86.8
Windows Print Spooler Information Disclosure Vulnerability
CVE-2026-32084NoNo--Important5.54.8
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-27927NoNo--Important7.86.8
CVE-2026-26184NoNo--Important7.86.8
CVE-2026-32069NoNo--Important7.86.8
CVE-2026-32074NoNo--Important7.86.8
CVE-2026-32078NoNo--Important7.86.8
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-26167NoNo--Important8.87.7
CVE-2026-32158NoNo--Important7.86.8
CVE-2026-32159NoNo--Important7.86.8
CVE-2026-32160NoNo--Important7.86.8
CVE-2026-26172NoNo--Important7.86.8
Windows Recovery Environment Security Feature Bypass Vulnerability
CVE-2026-20928NoNo--Important4.64.0
Windows Redirected Drive Buffering System Denial of Service Vulnerability
CVE-2026-32216NoNo--Important5.54.8
Windows Search Service Elevation of Privilege Vulnerability
CVE-2026-27909NoNo--Important7.86.8
Windows Sensor Data Service Elevation of Privilege Vulnerability
CVE-2026-26161NoNo--Important7.86.8
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-26174NoNo--Important7.06.1
CVE-2026-32224NoNo--Important7.06.1
Windows Server Update Service (WSUS) Tampering Vulnerability
CVE-2026-26154NoNo--Important7.56.5
Windows Shell Elevation of Privilege Vulnerability
CVE-2026-26165NoNo--Important7.06.1
CVE-2026-26166NoNo--Important7.06.1
CVE-2026-27918NoNo--Important7.86.8
Windows Shell Information Disclosure Vulnerability
CVE-2026-32151NoNo--Important6.55.7
Windows Shell Security Feature Bypass Vulnerability
CVE-2026-32225NoNo--Important8.87.7
Windows Shell Spoofing Vulnerability
CVE-2026-32202NoNo--Important4.33.8
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32082NoNo--Important7.06.1
CVE-2026-32083NoNo--Important7.06.1
CVE-2026-32068NoNo--Important7.06.1
Windows Snipping Tool Remote Code Execution Vulnerability
CVE-2026-32183NoNo--Important7.86.8
Windows Snipping Tool Spoofing Vulnerability
CVE-2026-33829NoNo--Moderate4.33.8
Windows Speech Brokered Api Elevation of Privilege Vulnerability
CVE-2026-32089NoNo--Important7.86.8
CVE-2026-32090NoNo--Important7.86.8
Windows Speech Runtime Elevation of Privilege Vulnerability
CVE-2026-32153NoNo--Important7.86.8
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-27907NoNo--Important7.86.8
CVE-2026-32076NoNo--Important7.86.8
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2026-33827NoNo--Critical8.17.1
Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability
CVE-2026-27908NoNo--Important7.06.1
CVE-2026-27921NoNo--Important7.06.1
Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27915NoNo--Important7.86.8
CVE-2026-27919NoNo--Important7.86.8
CVE-2026-32075NoNo--Important7.06.1
CVE-2026-27916NoNo--Important7.86.8
CVE-2026-27920NoNo--Important7.86.8
CVE-2026-32077NoNo--Important7.86.8
Windows UPnP Device Host Information Disclosure Vulnerability
CVE-2026-27925NoNo--Important6.55.7
Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-32156NoNo--Important7.46.4
Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability
CVE-2026-32223NoNo--Important6.85.9
Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32165NoNo--Important7.86.8
CVE-2026-27911NoNo--Important7.86.8
CVE-2026-32163NoNo--Important7.86.8
CVE-2026-32164NoNo--Important7.86.8
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
CVE-2026-23670NoNo--Important5.75.0
Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability
CVE-2026-27917NoNo--Important7.06.1
Windows WalletService Elevation of Privilege Vulnerability
CVE-2026-32080NoNo--Important7.06.1
Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-32222NoNo--Important7.86.8

Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu

Twitter |

Keywords: [microsoft patch Tuesday](/tag.html?tag=microsoft patch Tuesday)

0 comment(s)

Click HERE to learn more about classes Johannes is teaching for SANS

Comments

Login here to join the discussion.

Top of page

×

modal content

Diary Archives