Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Microsoft drops its second-largest monthly batch of defects on record  – CyberScoop
AttackFeed by Joe Wagner | Microsoft drops its second-largest monthly batch of defects on record  - CyberScoop

Microsoft drops its second-largest monthly batch of defects on record  – CyberScoop

Posted on April 14, 2026 By Matt Kapko No Comments on Microsoft drops its second-largest monthly batch of defects on record  – CyberScoop
Attack Feeds

Microsoft addressed 165 vulnerabilities affecting its various products and underlying systems, including one actively exploited vulnerability in Microsoft Office SharePoint, in this month’s Patch Tuesday update. 

“By my count, this is the second-largest monthly release in Microsoft’s history,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, wrote in a blog post Tuesday.

Microsoft didn’t explain why its monthly batch of patches grew so large this month, but Childs noted that many vulnerability programs are experiencing a significant increase in submissions found by artificial intelligence tools. “For us, our incoming rate has essentially tripled, making triage a challenge, to say the least,” he added. 

The zero-day vulnerability — CVE-2026-32201 — has a CVSS rating of 6.5 and allows attackers to view sensitive information and make changes to disclosed information. Microsoft said the improper input validation defect in Microsoft Office SharePoint allows unauthenticated attackers to perform spoofing over a network.

The Cybersecurity and Infrastructure Security Agency added the zero-day to its known exploited vulnerabilities catalog shortly after Microsoft’s disclosure. 

Microsoft also addressed a high-severity vulnerability — CVE-2026-33825 — that was publicly known at the time of release. The vendor said the defect in Microsoft Defender is more likely to be exploited and could allow unauthorized attackers to elevate privileges locally.

“What starts as a foothold can quickly become full system domination,” Jack Bicer, director of vulnerability research at Action1, said in a blog post about the vulnerability. 

“Once exploited, it allows full control over endpoints, enabling data exfiltration, disabling security tools and lateral movement across networks,” Bicer said.

Proof-of-concept exploit code for the defect is publicly available, which increases the likelihood of exploitation in the wild, he added.

Microsoft disclosed two critical vulnerabilities this month — CVE-2026-33824 affecting Windows IKE Extension and CVE-2026-26149 affecting Microsoft Power Apps — but designated both of the defects as less likely to be exploited.

More than three-quarters of the vulnerabilities disclosed this month are less likely to be exploited, according to Microsoft. Meanwhile, the company designated 19 vulnerabilities as more likely to be exploited.

The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

The post Microsoft drops its second-largest monthly batch of defects on record appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Fake Ledger Live app on Apple’s App Store stole $9.5M in crypto  – BleepingComputer
Next Post: Patch Tuesday, April 2026 Edition  – Krebs on Security ❯

You may also like

AttackFeed by Joe Wagner | A Victorian school teacher was applying for ‘heaps of rentals’ online – then someone accessed his bank account  - Data and computer security | The Guardian
Attack Feeds
A Victorian school teacher was applying for ‘heaps of rentals’ online – then someone accessed his bank account  – Data and computer security | The Guardian
February 6, 2026
AttackFeed by Joe Wagner | Congress looks to revive critical cyber program for rural electric utilities  - CyberScoop
Attack Feeds
Congress looks to revive critical cyber program for rural electric utilities  – CyberScoop
March 6, 2026
AttackFeed by Joe Wagner | Pressure mounts on Canvas as data leak extortion deadline looms  - CyberScoop
Attack Feeds
Pressure mounts on Canvas as data leak extortion deadline looms  – CyberScoop
May 11, 2026
AttackFeed by Joe Wagner | Discord-Linked Group Accessed Anthropic’s Claude Mythos AI in Vendor Breach  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Discord-Linked Group Accessed Anthropic’s Claude Mythos AI in Vendor Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More
April 22, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.