Skip to main content
QUIETLYTIC
Advisory

Microsoft Patch Tuesday April 2026: 687 Vulnerabilities Fixed

Microsoft's April 14, 2026 Patch Tuesday fixed 687 vulnerabilities (27 critical, 276 important) — 1 of them is confirmed under active exploitation, per CISA…

Microsoft Patch Tuesday April 2026: 687 Vulnerabilities Fixed — Advisory research covering CVE-2017-20230, CVE-2026-32186, CVE-2026-32213, CVE-2026-33105, CVE-2026-33107, CVE-2026-33819, CVE-2026-35431, CVE-2026-21515, CVE-2026-27140, CVE-2026-27143, CVE-2026-31478, CVE-2026-33824, CVE-2026-24303, CVE-2026-26135, CVE-2026-32210, CVE-2026-33102, CVE-2026-32211, CVE-2026-32157, CVE-2026-26150, CVE-2026-32173, CVE-2026-32190, CVE-2026-33114, CVE-2026-33115, CVE-2026-33827, CVE-2026-32172, CVE-2026-33826, CVE-2026-23666, CVE-2026-40372, CVE-2026-26149, CVE-2026-31593, CVE-2026-26167, CVE-2026-26178, CVE-2026-32171, CVE-2026-32225, CVE-2026-33120, CVE-2026-27928, CVE-2026-34445, CVE-2026-5435, CVE-2026-23401, CVE-2026-40706, CVE-2026-32091, CVE-2026-32162, CVE-2026-32221, CVE-2026-32316, CVE-2026-33845, CVE-2026-34982, CVE-2026-41604, CVE-2026-31414, CVE-2026-31416, CVE-2026-31417, CVE-2026-31418, CVE-2026-35469, CVE-2026-40393, CVE-2026-6100, CVE-2026-27912, CVE-2026-23406, CVE-2026-23407, CVE-2026-23408, CVE-2026-23410, CVE-2026-23411, CVE-2026-23447, CVE-2026-31408, CVE-2026-31427, CVE-2026-31430, CVE-2026-31432, CVE-2026-31446, CVE-2026-31454, CVE-2026-31473, CVE-2026-31483, CVE-2026-31493, CVE-2026-31506, CVE-2026-31508, CVE-2026-31530, CVE-2026-31532, CVE-2026-31548, CVE-2026-31578, CVE-2026-31584, CVE-2026-31589, CVE-2026-31609, CVE-2026-31617, CVE-2026-31630, CVE-2026-31648, CVE-2026-31675, CVE-2026-31688, CVE-2026-34001, CVE-2026-39853, CVE-2026-6846, CVE-2026-20930, CVE-2026-23657, CVE-2026-26143, CVE-2026-26153, CVE-2026-26156, CVE-2026-26159, CVE-2026-26160, CVE-2026-26161, CVE-2026-26162, CVE-2026-26163, CVE-2026-26168, CVE-2026-26170, CVE-2026-26172, CVE-2026-26176, CVE-2026-26179, CVE-2026-26180, CVE-2026-26181, CVE-2026-26183, CVE-2026-26184, CVE-2026-27907, CVE-2026-27909, CVE-2026-27910, CVE-2026-27911, CVE-2026-27914, CVE-2026-27915, CVE-2026-27916, CVE-2026-27918, CVE-2026-27919, CVE-2026-27920, CVE-2026-27923, CVE-2026-27924, CVE-2026-27927, CVE-2026-32069, CVE-2026-32074, CVE-2026-32076, CVE-2026-32077, CVE-2026-32078, CVE-2026-32089, CVE-2026-32090, CVE-2026-32152, CVE-2026-32153, CVE-2026-32154, CVE-2026-32155, CVE-2026-32158, CVE-2026-32159, CVE-2026-32160, CVE-2026-32163, CVE-2026-32164, CVE-2026-32165, CVE-2026-32168, CVE-2026-32183, CVE-2026-32184, CVE-2026-32189, CVE-2026-32192, CVE-2026-32197, CVE-2026-32198, CVE-2026-32199, CVE-2026-32200, CVE-2026-32222, CVE-2026-33095, CVE-2026-33098, CVE-2026-33101, CVE-2026-33825
Severity
Critical
Confidence
High
Status
Active

Full CVE Roster

All 150 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search — 2 flagged as actively exploited (KEV).

CVE ID Title CVSS Severity KEV
CVE-2017-20230 Storable versions before 3.05 for Perl has a stack overflow 10.0 critical
CVE-2026-32186 Microsoft Bing Elevation of Privilege Vulnerability 10.0 critical
CVE-2026-32213 Azure AI Foundry Elevation of Privilege Vulnerability 10.0 critical
CVE-2026-33105 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 10.0 critical
CVE-2026-33107 Azure Databricks Elevation of Privilege Vulnerability 10.0 critical
CVE-2026-33819 Microsoft Bing Remote Code Execution Vulnerability 10.0 critical
CVE-2026-35431 Microsoft Entra ID Entitlement Management Spoofing Vulnerability 10.0 critical
CVE-2026-21515 Azure IoT Central Elevation of Privilege Vulnerability 9.9 critical
CVE-2026-27140 Code execution vulnerability in SWIG code generation in cmd/go 9.8 critical
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile 9.8 critical
CVE-2026-31478 ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() 9.8 critical
CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability 9.8 critical Yes
CVE-2026-24303 Microsoft Partner Center Elevation of Privilege Vulnerability 9.6 critical
CVE-2026-26135 Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability 9.6 critical
CVE-2026-32210 Microsoft Dynamics 365 (online) Spoofing Vulnerability 9.3 critical
CVE-2026-33102 Microsoft 365 Copilot Elevation of Privilege Vulnerability 9.3 critical
CVE-2026-32211 Azure MCP Server Information Disclosure Vulnerability 9.1 critical
CVE-2026-32157 Remote Desktop Client Remote Code Execution Vulnerability 8.8 critical
CVE-2026-26150 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability 8.6 critical
CVE-2026-32173 Azure SRE Agent Information Disclosure Vulnerability 8.6 critical
CVE-2026-32190 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-33114 Microsoft Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-33115 Microsoft Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-33827 Windows TCP/IP Remote Code Execution Vulnerability 8.1 critical
CVE-2026-32172 Microsoft Power Apps Remote Code Execution Vulnerability 8.0 critical
CVE-2026-33826 Windows Active Directory Remote Code Execution Vulnerability 8.0 critical
CVE-2026-23666 .NET Framework Denial of Service Vulnerability 7.5 critical
CVE-2026-40372 ASP.NET Core Elevation of Privilege Vulnerability 9.1 high
CVE-2026-26149 Microsoft Power Apps Desktop Client Spoofing Vulnerability 9.0 high
CVE-2026-31593 KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU 8.8 high
CVE-2026-26167 Windows Push Notifications Elevation of Privilege Vulnerability 8.8 high
CVE-2026-26178 Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability 8.8 high
CVE-2026-32171 Azure Logic Apps Elevation of Privilege Vulnerability 8.8 high
CVE-2026-32225 Windows Shell Security Feature Bypass Vulnerability 8.8 high
CVE-2026-33120 Microsoft SQL Server Remote Code Execution Vulnerability 8.8 high
CVE-2026-27928 Windows Hello Security Feature Bypass Vulnerability 8.7 high
CVE-2026-34445 ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings. 8.6 high
CVE-2026-5435 Potential buffer overflow in ns_sprintrrf TSIG handling path 8.6 high
CVE-2026-23401 KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE 8.4 high
CVE-2026-40706 In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs. 8.4 high
CVE-2026-32091 Microsoft Brokering File System Elevation of Privilege Vulnerability 8.4 high
CVE-2026-32162 Windows COM Elevation of Privilege Vulnerability 8.4 high
CVE-2026-32221 Windows Graphics Component Remote Code Execution Vulnerability 8.4 high
CVE-2026-32316 jq: Integer overflow in jvp_string_append() allows Heap-based Buffer Overflow 8.2 high
CVE-2026-33845 Gnutls: gnutls: denial of service via dtls zero-length fragment 8.2 high
CVE-2026-34982 Vim modeline bypass via various options affects Vim < 9.2.0276 8.2 high
CVE-2026-41604 Apache Thrift: Swift Range crash in skip() 8.2 high
CVE-2026-31414 netfilter: nf_conntrack_expect: use expect->helper 8.1 high
CVE-2026-31416 netfilter: nfnetlink_log: account for netlink header size 8.1 high
CVE-2026-31417 net/x25: Fix overflow when accumulating packets 8.1 high
CVE-2026-31418 netfilter: ipset: drop logically empty buckets in mtype_del 8.1 high
CVE-2026-35469 SpdyStream: DOS on CRI 8.1 high
CVE-2026-40393 In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca. 8.1 high
CVE-2026-6100 Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure 8.1 high
CVE-2026-27912 Windows Kerberos Elevation of Privilege Vulnerability 8.0 high
CVE-2026-23406 apparmor: fix side-effect bug in match_char() macro usage 7.8 high
CVE-2026-23407 apparmor: fix missing bounds check on DEFAULT table in verify_dfa() 7.8 high
CVE-2026-23408 apparmor: Fix double free of ns_name in aa_replace_profiles() 7.8 high
CVE-2026-23410 apparmor: fix race on rawdata dereference 7.8 high
CVE-2026-23411 apparmor: fix race between freeing data and fs accessing it 7.8 high
CVE-2026-23447 net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check 7.8 high
CVE-2026-31408 Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold 7.8 high
CVE-2026-31427 netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp 7.8 high
CVE-2026-31430 X.509: Fix out-of-bounds access when parsing extensions 7.8 high
CVE-2026-31432 ksmbd: fix OOB write in QUERY_INFO for compound requests 7.8 high
CVE-2026-31446 ext4: fix use-after-free in update_super_work when racing with umount 7.8 high
CVE-2026-31454 xfs: save ailp before dropping the AIL lock in push callbacks 7.8 high
CVE-2026-31473 media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex 7.8 high
CVE-2026-31483 s390/syscalls: Add spectre boundary for syscall dispatch table 7.8 high
CVE-2026-31493 RDMA/efa: Fix use of completion ctx after free 7.8 high
CVE-2026-31506 net: bcmasp: fix double free of WoL irq 7.8 high
CVE-2026-31508 net: openvswitch: Avoid releasing netdev before teardown completes 7.8 high
CVE-2026-31530 cxl/port: Fix use after free of parent_port in cxl_detach_ep() 7.8 high
CVE-2026-31532 can: raw: fix ro->uniq use-after-free in raw_rcv() 7.8 high
CVE-2026-31548 wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down 7.8 high
CVE-2026-31578 media: as102: fix to not free memory after the device is registered in as102_usb_probe() 7.8 high
CVE-2026-31584 media: mediatek: vcodec: fix use-after-free in encoder release path 7.8 high
CVE-2026-31589 mm: call ->free_folio() directly in folio_unmap_invalidate() 7.8 high
CVE-2026-31609 smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush() 7.8 high
CVE-2026-31617 usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() 7.8 high
CVE-2026-31630 rxrpc: proc: size address buffers for %pISpc output 7.8 high
CVE-2026-31648 mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() 7.8 high
CVE-2026-31675 net/sched: sch_netem: fix out-of-bounds access in packet corruption 7.8 high
CVE-2026-31688 driver core: enforce device_lock for driver_match_device() 7.8 high
CVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption 7.8 high
CVE-2026-39853 osslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification 7.8 high
CVE-2026-6846 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing 7.8 high
CVE-2026-20930 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-23657 Microsoft Word Remote Code Execution Vulnerability 7.8 high
CVE-2026-26143 Microsoft PowerShell Security Feature Bypass Vulnerability 7.8 high
CVE-2026-26153 Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26156 Windows Hyper-V Remote Code Execution Vulnerability 7.8 high
CVE-2026-26159 Remote Desktop Licensing Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26160 Remote Desktop Licensing Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26161 Windows Sensor Data Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26162 Windows OLE Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26163 Windows Kernel Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26168 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26170 PowerShell Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26172 Windows Push Notifications Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26176 Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26179 Windows Kernel Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26180 Windows Kernel Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26181 Microsoft Brokering File System Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26183 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-26184 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27907 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27909 Windows Search Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27910 Windows Installer Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27911 Windows User Interface Core Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27914 Microsoft Management Console Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27915 Windows UPnP Device Host Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27916 Windows UPnP Device Host Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27918 Windows Shell Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27919 Windows UPnP Device Host Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27920 Windows UPnP Device Host Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27923 Desktop Window Manager Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27924 Desktop Window Manager Elevation of Privilege Vulnerability 7.8 high
CVE-2026-27927 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32069 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32074 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32076 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32077 Windows UPnP Device Host Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32078 Windows Projected File System Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32089 Windows Speech Brokered Api Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32090 Windows Speech Brokered Api Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32152 Desktop Window Manager Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32154 Desktop Window Manager Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32155 Desktop Window Manager Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32158 Windows Push Notifications Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32159 Windows Push Notifications Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32160 Windows Push Notifications Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32163 Windows User Interface Core Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32164 Windows User Interface Core Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32165 Windows User Interface Core Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32168 Azure Monitor Agent Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32183 Windows Snipping Tool Remote Code Execution Vulnerability 7.8 high
CVE-2026-32184 Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32189 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-32192 Azure Monitor Agent Elevation of Privilege Vulnerability 7.8 high
CVE-2026-32197 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-32198 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-32199 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-32200 Microsoft PowerPoint Remote Code Execution Vulnerability 7.8 high
CVE-2026-32222 Windows Win32k Elevation of Privilege Vulnerability 7.8 high
CVE-2026-33095 Microsoft Word Remote Code Execution Vulnerability 7.8 high
CVE-2026-33098 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-33101 Windows Print Spooler Elevation of Privilege Vulnerability 7.8 high
CVE-2026-33825 Microsoft Defender Elevation of Privilege Vulnerability 7.8 high Yes

Microsoft’s April 14, 2026 Patch Tuesday release covers 687 CVEs: 27 rated critical, 276 rated important, and 252 rated moderate. Of these, 1 of them is confirmed under active exploitation.

Severity Breakdown

Severity Count
Critical 27
Important 276
Moderate 252
Actively exploited (CISA KEV) 1

Highest-Severity Vulnerabilities

Top 20 of 687 total, by CVSS/severity:

CVE Title CVSS
CVE-2017-20230 Storable versions before 3.05 for Perl has a stack overflow 10.0
CVE-2026-32186 Microsoft Bing Elevation of Privilege Vulnerability 10.0
CVE-2026-32213 Azure AI Foundry Elevation of Privilege Vulnerability 10.0
CVE-2026-33105 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 10.0
CVE-2026-33107 Azure Databricks Elevation of Privilege Vulnerability 10.0
CVE-2026-33819 Microsoft Bing Remote Code Execution Vulnerability 10.0
CVE-2026-35431 Microsoft Entra ID Entitlement Management Spoofing Vulnerability 10.0
CVE-2026-21515 Azure IoT Central Elevation of Privilege Vulnerability 9.9
CVE-2026-27140 Code execution vulnerability in SWIG code generation in cmd/go 9.8
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile 9.8
CVE-2026-31478 ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() 9.8
CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability 9.8 — actively exploited (CISA KEV)
CVE-2026-24303 Microsoft Partner Center Elevation of Privilege Vulnerability 9.6
CVE-2026-26135 Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability 9.6
CVE-2026-32210 Microsoft Dynamics 365 (online) Spoofing Vulnerability 9.3
CVE-2026-33102 Microsoft 365 Copilot Elevation of Privilege Vulnerability 9.3
CVE-2026-32211 Azure MCP Server Information Disclosure Vulnerability 9.1
CVE-2026-40372 ASP.NET Core Elevation of Privilege Vulnerability 9.1
CVE-2026-26149 Microsoft Power Apps Desktop Client Spoofing Vulnerability 9.0
CVE-2026-32157 Remote Desktop Client Remote Code Execution Vulnerability 8.8

CVSS scores are sourced directly from Microsoft’s CVRF data as of April 14, 2026; exploitation status is cross-checked against CISA’s KEV catalog. Later re-scoring by NVD can shift a CVE’s score after this report was generated.

Why This Matters

With 1 vulnerability already under active exploitation, prioritizing this month’s patches isn’t optional for exposed systems — attackers are demonstrably already using at least one of these flaws. Organizations should prioritize the critical- and important-rated CVEs above, especially any with public proof-of-concept exploits.

Frequently Asked Questions

How many vulnerabilities did Microsoft patch in April 2026? 687 CVEs, per Microsoft’s April 14, 2026 Patch Tuesday release.

Were any April 2026 Patch Tuesday vulnerabilities actively exploited? Yes — 1 of them is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog as of April 14, 2026.


Data sourced from Microsoft Security Response Center (MSRC) CVRF v3.0 and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated April 14, 2026. See more vulnerability research.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 Microsoft Security Response Center (MSRC)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools