Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryactively-exploited-vulnerabilitygovernment-vulnerability-catalogproof-of-concept-release

Microsoft Patches 163 Flaws Including Exploited SharePoint Bug and Defender Zero-Day

Updated 1mo agoFirst seen Apr 15, 20266 sources

Microsoft released fixes for 163 vulnerabilities in its April Patch Tuesday update, marking one of its largest security releases on record. The bundle includes 8 Critical flaws, 154 Important issues, and 1 Moderate bug, with seven of the Critical vulnerabilities enabling remote code execution across products and components including Windows TCP/IP, Windows IKE Service Extensions, Active Directory, Remote Desktop Client, Microsoft Office, and Microsoft Word. Belgian authorities urged organizations to apply the updates immediately.

The most urgent issues include CVE-2026-32201, an actively exploited Microsoft SharePoint Server vulnerability that was added to CISA’s Known Exploited Vulnerabilities catalog, and CVE-2026-33825 in Microsoft Defender, a publicly disclosed zero-day tied to proof-of-concept code associated with the BlueHammer exploit. Microsoft also shipped Windows 11 cumulative updates with security hardening changes, including safer handling of .rdp files and improved visibility into Secure Boot certificates, while the broader patch set addressed numerous elevation-of-privilege and security feature bypass flaws that could support post-compromise escalation.

Share:
Microsoft Patches 163 Flaws Including Exploited SharePoint Bug and Defender Zero-Day
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 22, 20261mo ago

Shadowserver finds 1,300+ SharePoint servers still unpatched after April fixes

After Microsoft's April 2026 Patch Tuesday, Shadowserver reported that more than 1,300 internet-exposed SharePoint servers remained unpatched against CVE-2026-32201. The finding highlighted continued exposure of vulnerable SharePoint Enterprise Server 2016, SharePoint Server 2019, and Subscription Edition systems despite available fixes.

Microsoft Patch Still Leaves 1,300 SharePoint Servers Exposed
Apr 15, 20262mo ago

Microsoft ships Windows 11 hardening updates with April 2026 patches

Alongside Patch Tuesday, Microsoft released Windows 11 cumulative updates containing security hardening changes. These included safer handling of .rdp files and improvements to Secure Boot certificate visibility.

Microsoft releases April 2026 Patch Tuesday fixes for 163 CVEs

Microsoft's April 2026 Patch Tuesday addressed 163 vulnerabilities, including eight Critical flaws, one publicly disclosed zero-day, and one vulnerability under active exploitation. The release was described as the second-largest Patch Tuesday on record.

CISA catalogs SharePoint flaw CVE-2026-32201 as actively exploited

CVE-2026-32201 in Microsoft SharePoint Server was added to CISA's Known Exploited Vulnerabilities Catalog after evidence of active exploitation in the wild. The designation elevated the flaw's urgency ahead of or alongside Microsoft's April 2026 fixes.

BlueHammer PoC publicly discloses Microsoft Defender flaw CVE-2026-33825

CVE-2026-33825 in Microsoft Defender was publicly disclosed with proof-of-concept code associated with the "BlueHammer" exploit. This made it one of the most urgent issues addressed in Microsoft's April 2026 security updates.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

50 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.