⚡ TL;DR | Go Straight to the April 2026 Patch Tuesday Audit Report
Patch Tuesday is once again upon us. As always, our team has put together the monthly Patch Tuesday Report to help you manage your update progress. The audit report gives you a quick and clear overview of your Windows machines and their patching status. The April 2026 edition of Patch Tuesday brings us 171 fixes, with 8 rated as critical. We’ve listed the most important changes below.
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-32201 is the only actively exploited vulnerability in this month’s release. The flaw stems from improper input validation in Microsoft Office SharePoint, allowing an unauthenticated attacker to perform spoofing over a network with no user interaction required. Microsoft has confirmed exploitation in the wild, so despite the moderate CVSS score of 6.5, this one should be at the top of every SharePoint admin’s patching queue.
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2026-33825 is the sole publicly disclosed vulnerability this month and is also rated as “Exploitation More Likely.” The issue lies in insufficient access control granularity within Microsoft Defender, allowing an authenticated attacker with low-level privileges to elevate locally. With a CVSS score of 7.8 and public disclosure putting this squarely on the radar of threat actors, patching is urgent. It is somewhat ironic that an endpoint security product is itself the weak link this time around.
Windows Active Directory Remote Code Execution Vulnerability
CVE-2026-33826 is a critical remote code execution flaw in Windows Active Directory caused by improper input validation. An authenticated attacker with low privileges can execute arbitrary code over an adjacent network without any user interaction. At a CVSS score of 8.0 and rated “Exploitation More Likely,” this vulnerability poses serious risk to enterprise environments where Active Directory is the backbone of identity and access management. The adjacent-network requirement limits mass exploitation over the internet, but internal network compromise scenarios, such as a lateral move after initial access, make this a high-priority fix.
Run the Patch Tuesday April 2026 Audit
To help manage your update progress, we’ve created the Patch Tuesday Audit that checks if the assets in your network are on the latest patch updates. The report has been color-coded to see which machines are up-to-date and which ones still need to be updated. As always, system administrators are urged to update their environment as soon as possible to ensure all endpoints are secured.
The Lansweeper Patch Tuesday report is automatically added to your Lansweeper Site. Lansweeper Sites is included in all our licenses without any additional cost and allows you to federate all your installations into one single view so all you need to do is look at one report, automatically added every patch Tuesday!
Patch Tuesday April 2026 CVE Codes & Titles
| CVE | Title |
| CVE-2023-20585 | AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability |
| CVE-2025-6965 | Integer Truncation on SQLite |
| CVE-2026-0390 | UEFI Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-20806 | Windows COM Server Information Disclosure Vulnerability |
| CVE-2026-20928 | Windows Recovery Environment Security Feature Bypass Vulnerability |
| CVE-2026-20930 | Windows Management Services Elevation of Privilege Vulnerability |
| CVE-2026-20945 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-21637 | HackerOne: CVE-2026-21637 TLS PSK/ALPN Callback Exceptions Bypass Error Handlers |
| CVE-2026-23653 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-23657 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-23666 | .NET Framework Denial of Service Vulnerability |
| CVE-2026-23670 | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
| CVE-2026-25184 | Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability |
| CVE-2026-25250 | MITRE: CVE-2026-25250 Secure Boot disable Eazy Fix |
| CVE-2026-26143 | Microsoft PowerShell Remote Code Execution Vulnerability |
| CVE-2026-26149 | Microsoft Power Apps Remote Code Execution Vulnerability |
| CVE-2026-26151 | Remote Desktop Spoofing Vulnerability |
| CVE-2026-26152 | Windows Cryptographic Services Elevation of Privilege Vulnerability |
| CVE-2026-26153 | Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability |
| CVE-2026-26154 | Windows Server Update Service Denial of Service Vulnerability |
| CVE-2026-26155 | Windows Local Security Authority Subsystem Service (LSASS) Information Disclosure Vulnerability |
| CVE-2026-26156 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2026-26159 | Windows Remote Desktop Licensing Service Elevation of Privilege Vulnerability |
| CVE-2026-26160 | Windows Remote Desktop Licensing Service Elevation of Privilege Vulnerability |
| CVE-2026-26161 | Windows Sensor Data Service Elevation of Privilege Vulnerability |
| CVE-2026-26162 | Windows OLE Elevation of Privilege Vulnerability |
| CVE-2026-26163 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-26165 | Windows Shell Elevation of Privilege Vulnerability |
| CVE-2026-26166 | Windows Shell Elevation of Privilege Vulnerability |
| CVE-2026-26167 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-26168 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-26169 | Windows Kernel Memory Information Disclosure Vulnerability |
| CVE-2026-26170 | Microsoft PowerShell Elevation of Privilege Vulnerability |
| CVE-2026-26171 | .NET Denial of Service Vulnerability |
| CVE-2026-26172 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-26173 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-26174 | Windows Server Update Service Elevation of Privilege Vulnerability |
| CVE-2026-26175 | Windows Boot Manager Information Disclosure Vulnerability |
| CVE-2026-26176 | Windows Client Side Caching Driver (csc.sys) Elevation of Privilege Vulnerability |
| CVE-2026-26177 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-26178 | Windows Advanced Rasterization Platform Remote Code Execution Vulnerability |
| CVE-2026-26179 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-26180 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-26181 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-26182 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-26183 | Windows RPC API Elevation of Privilege Vulnerability |
| CVE-2026-26184 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-27906 | Windows Hello Security Feature Bypass Vulnerability |
| CVE-2026-27907 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
| CVE-2026-27908 | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability |
| CVE-2026-27909 | Windows Search Service Elevation of Privilege Vulnerability |
| CVE-2026-27910 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-27911 | Windows User Interface Core Elevation of Privilege Vulnerability |
| CVE-2026-27912 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2026-27913 | Windows BitLocker Security Feature Bypass Vulnerability |
| CVE-2026-27914 | Microsoft Management Console Elevation of Privilege Vulnerability |
| CVE-2026-27915 | Windows UPnP Device Host Elevation of Privilege Vulnerability |
| CVE-2026-27916 | Windows UPnP Device Host Elevation of Privilege Vulnerability |
| CVE-2026-27917 | Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability |
| CVE-2026-27918 | Windows Shell Elevation of Privilege Vulnerability |
| CVE-2026-27919 | Windows UPnP Device Host Elevation of Privilege Vulnerability |
| CVE-2026-27920 | Windows UPnP Device Host Elevation of Privilege Vulnerability |
| CVE-2026-27921 | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability |
| CVE-2026-27922 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-27923 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-27924 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-27925 | Windows UPnP Device Host Information Disclosure Vulnerability |
| CVE-2026-27926 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-27927 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-27928 | Windows Hello Spoofing Vulnerability |
| CVE-2026-27929 | Windows LUAFV Elevation of Privilege Vulnerability |
| CVE-2026-27930 | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-27931 | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-32068 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
| CVE-2026-32069 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-32070 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2026-32071 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
| CVE-2026-32072 | Active Directory Spoofing Vulnerability |
| CVE-2026-32073 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-32074 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-32075 | Windows UPnP Device Host Elevation of Privilege Vulnerability |
| CVE-2026-32076 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
| CVE-2026-32077 | Windows UPnP Device Host Elevation of Privilege Vulnerability |
| CVE-2026-32078 | Windows Projected File System Elevation of Privilege Vulnerability |
| CVE-2026-32079 | Web Account Manager Information Disclosure Vulnerability |
| CVE-2026-32080 | Windows WalletService Elevation of Privilege Vulnerability |
| CVE-2026-32081 | Package Catalog Information Disclosure Vulnerability |
| CVE-2026-32082 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
| CVE-2026-32083 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
| CVE-2026-32084 | Windows File Explorer Information Disclosure Vulnerability |
| CVE-2026-32085 | Windows Remote Procedure Call Information Disclosure Vulnerability |
| CVE-2026-32086 | Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
| CVE-2026-32087 | Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
| CVE-2026-32088 | Windows Biometric Service Elevation of Privilege Vulnerability |
| CVE-2026-32089 | Windows Speech Brokered Api Elevation of Privilege Vulnerability |
| CVE-2026-32090 | Windows Speech Brokered Api Elevation of Privilege Vulnerability |
| CVE-2026-32091 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-32093 | Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
| CVE-2026-32149 | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-32150 | Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability |
| CVE-2026-32151 | Windows Shell Information Disclosure Vulnerability |
| CVE-2026-32152 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-32153 | Windows Speech Elevation of Privilege Vulnerability |
| CVE-2026-32154 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-32155 | Desktop Window Manager Elevation of Privilege Vulnerability |
| CVE-2026-32156 | Windows UPnP Device Host Elevation of Privilege Vulnerability |
| CVE-2026-32157 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2026-32158 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-32159 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-32160 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-32162 | Windows COM Elevation of Privilege Vulnerability |
| CVE-2026-32163 | Windows User Interface Core Elevation of Privilege Vulnerability |
| CVE-2026-32164 | Windows User Interface Core Elevation of Privilege Vulnerability |
| CVE-2026-32165 | Windows User Interface Core Elevation of Privilege Vulnerability |
| CVE-2026-32167 | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-32168 | Azure Monitor Agent Elevation of Privilege Vulnerability |
| CVE-2026-32171 | Azure Logic Apps Remote Code Execution Vulnerability |
| CVE-2026-32176 | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-32178 | .NET Spoofing Vulnerability |
| CVE-2026-32181 | Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
| CVE-2026-32183 | Windows Snipping Tool Remote Code Execution Vulnerability |
| CVE-2026-32184 | Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability |
| CVE-2026-32188 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-32189 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-32190 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-32192 | Azure Monitor Agent Elevation of Privilege Vulnerability |
| CVE-2026-32195 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-32196 | Windows Admin Center Spoofing Vulnerability |
| CVE-2026-32197 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-32198 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-32199 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-32200 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2026-32201 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-32202 | Windows Shell Spoofing Vulnerability |
| CVE-2026-32203 | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2026-32212 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
| CVE-2026-32214 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
| CVE-2026-32215 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-32216 | Windows Redirected Drive Buffering System Denial of Service Vulnerability |
| CVE-2026-32217 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-32218 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-32219 | Microsoft Brokering File System Elevation of Privilege Vulnerability |
| CVE-2026-32220 | UEFI Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-32221 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-32222 | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2026-32223 | Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability |
| CVE-2026-32224 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability |
| CVE-2026-32225 | Windows Shell Security Feature Bypass Vulnerability |
| CVE-2026-32226 | .NET Framework Denial of Service Vulnerability |
| CVE-2026-32631 | GitHub: CVE-2026-32631 Git for Windows credential helper URI mishandling |
| CVE-2026-33095 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-33096 | Windows HTTP.sys Denial of Service Vulnerability |
| CVE-2026-33098 | Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability |
| CVE-2026-33099 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-33100 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
| CVE-2026-33101 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2026-33103 | Microsoft Dynamics 365 (on-premises) Information Disclosure Vulnerability |
| CVE-2026-33104 | Win32k Elevation of Privilege Vulnerability |
| CVE-2026-33114 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-33115 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2026-33116 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2026-33120 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-33822 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability |
| CVE-2026-33825 | Microsoft Defender Elevation of Privilege Vulnerability |
| CVE-2026-33826 | Windows Active Directory Remote Code Execution Vulnerability |
| CVE-2026-33827 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2026-33829 | Windows Snipping Tool Spoofing Vulnerability |