Microsoft's April 2026 Patch Tuesday Drops 163 CVEs — SharePoint Zero-Day Exploited, IKE RCE Scores CVSS 9.8
Microsoft's second-largest Patch Tuesday on record patches 163 CVEs including an actively exploited SharePoint spoofing zero-day and a critical CVSS 9.8 remote code execution flaw in Windows IKE. Patch now.
Microsoft’s April 2026 Patch Tuesday is the second-largest on record: 163 CVEs patched, eight rated Critical, 154 Important, and two zero-days — one already being exploited in the wild.
CVE-2026-32201 — Actively Exploited SharePoint Spoofing Zero-Day (CVSS 6.5)
This spoofing vulnerability affects Microsoft SharePoint Server 2016, 2019, and the Subscription Edition. Microsoft has confirmed exploitation in the wild and released patches for all three versions. A CVSS of 6.5 understates the real-world risk: SharePoint spoofing bugs are routinely chained with privilege escalation vulnerabilities in multi-stage attacks that end at domain admin. If you’re running on-premises SharePoint, this is your top priority this cycle, regardless of whether it’s internet-facing.
CVE-2026-33824 — Windows IKE Service Extensions RCE (CVSS 9.8, Critical)
Remote code execution in the Windows Internet Key Exchange Service Extensions — the protocol engine underpinning IPsec and VPN negotiation on Windows. No user interaction required. Score: 9.8. Any Windows system with IPsec policies, VPN services, Always-On VPN, or DirectAccess configured is potentially exposed. Unauthenticated exploitation is viable for network-accessible endpoints.
Weaponized proof-of-concept code for IKE-class vulnerabilities typically appears on criminal forums within 72 hours of Patch Tuesday. Do not wait on this one.
CVE-2026-33825 — BlueHammer Privilege Escalation Now Officially Patched
The kernel-mode driver privilege escalation bug a researcher published to GitHub on April 3rd — after a disclosure dispute with Microsoft — now has an official fix. If you haven’t locked down unsigned kernel-mode driver execution since that disclosure, this update is urgent.
The scale matters
163 CVEs in a single release puts April 2026 just below the all-time Patch Tuesday record set in October 2025. This cadence isn’t slowing. Eight critical patches, two confirmed zero-days, and a 9.8 IKE RCE is not a routine month — this is a month where organizations that skip patching windows will get hurt.
What to do now
- Sync your WSUS catalog and push the April 2026 update rollup immediately
- Prioritize CVE-2026-33824 on VPN gateways, domain controllers, DirectAccess endpoints, and any network edge server with IPsec enabled
- Apply SharePoint patches regardless of internet exposure — internal attackers and lateral movement both reach on-premises SharePoint
- Check CISA’s Known Exploited Vulnerabilities catalog for any additional compliance deadlines tied to this patch batch
- Verify your EDR is logging IKE exchange anomalies — unusual negotiation failures and memory-related security events are early indicators of exploitation attempts
Full technical breakdown is available in Microsoft’s Security Update Guide and Tenable’s April 2026 Patch Tuesday analysis.
Related reading
- Cybersecurity Microsoft Exchange Zero-Day CVE-2026-42897 Actively Exploited — No Full Patch, Automatic Mitigation Only
- Cybersecurity Microsoft Defender Hit by 'RoguePlanet' Zero-Day — CVE-2026-50656, No Patch Yet
- Cybersecurity CVE-2026-42897 (CVSS 8.1): Microsoft Exchange OWA Zero-Day Actively Exploited — No Patch Available