Threat intelligence

Microsoft Security Bulletin Coverage for April 2026

by Security News

Overview

Microsoft’s April 2026 Patch Tuesday has 163 vulnerabilities, of which 94 are Elevation of Privilege. SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of April 2026 and has produced coverage for 14 of the reported vulnerabilities.

Vulnerabilities with Detections

CVE

CVE Title

Signature

CVE-2026-26169Windows Kernel Memory Information Disclosure VulnerabilityASPY 7204 Exploit-exe exe.MP_509
CVE-2026-27908Windows TDI Translation Driver (tdx.sys) Elevation of Privilege VulnerabilityASPY 7205 Exploit-exe exe.MP_510
CVE-2026-27909Windows Search Service Elevation of Privilege VulnerabilityASPY 7206 Exploit-exe exe.MP_511
CVE-2026-27914Microsoft Management Console Elevation of Privilege VulnerabilityASPY 7207 Exploit-exe exe.MP_512
CVE-2026-27921Windows TDI Translation Driver (tdx.sys) Elevation of Privilege VulnerabilityASPY 7208 Exploit-exe exe.MP_513
CVE-2026-32070Windows Common Log File System Driver Elevation of Privilege VulnerabilityASPY 7209 Exploit-exe exe.MP_514
CVE-2026-32093Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege VulnerabilityASPY 7210 Exploit-exe exe.MP_515
CVE-2026-32152Desktop Window Manager Elevation of Privilege VulnerabilityASPY 678 Exploit-exe exe.MP_508
CVE-2026-32154Desktop Window Manager Elevation of Privilege VulnerabilityASPY 7211 Exploit-exe exe.MP_516
CVE-2026-32162Windows COM Elevation of Privilege VulnerabilityASPY 677 Exploit-exe exe.MP_507
CVE-2026-32201Microsoft SharePoint Server Spoofing VulnerabilityIPS 4617 Microsoft SharePoint Server Spoofing (CVE-2026-32201)
CVE-2026-32202Windows Shell Spoofing VulnerabilityASPY 676 Exploit-exe exe.MP_506
CVE-2026-32225Windows Shell Security Feature Bypass VulnerabilityASPY 675 Exploit-exe exe.MP_505
CVE-2026-33825Microsoft Defender Elevation of Privilege VulnerabilityASPY 674 Exploit-exe exe.MP_504

 

 

Release Breakdown

The vulnerabilities can be classified into the following categories:

 

Apr_2026_impact_1.png

 

 

Apr_2026_severity_2.png

For April there are 8 critical and 154 important vulnerabilities.

 

Apr_2026_Vul_count_3.png

 

April_expl_dis_4.png

Microsoft tracks vulnerabilities that are being actively exploited at the time of discovery and those that have been disclosed publicly before the patch Tuesday release for each month. The above chart displays these metrics as seen each month.

 

 

Apr_2026_expl_assesment_5.png

 

Release Detailed Breakdown

Denial of Service Vulnerabilities

CVECVE Title
CVE-2026-23666.NET Framework Denial of Service Vulnerability
CVE-2026-26171.NET Denial of Service Vulnerability
CVE-2026-32071Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-32181Connected User Experiences and Telemetry Service Denial of Service Vulnerability
CVE-2026-32203.NET and Visual Studio Denial of Service Vulnerability
CVE-2026-32226.NET Framework Denial of Service Vulnerability
CVE-2026-33096HTTP.sys Denial of Service Vulnerability
CVE-2026-33116.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

 

Elevation of Privilege Vulnerabilities

CVECVE Title
CVE-2026-20930Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-25184Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability
CVE-2026-26152Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2026-26153Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability
CVE-2026-26159Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVE-2026-26160Remote Desktop Licensing Service Elevation of Privilege Vulnerability
CVE-2026-26161Windows Sensor Data Service Elevation of Privilege Vulnerability
CVE-2026-26162Windows OLE Elevation of Privilege Vulnerability
CVE-2026-26163Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26165Windows Shell Elevation of Privilege Vulnerability
CVE-2026-26166Windows Shell Elevation of Privilege Vulnerability
CVE-2026-26167Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-26168Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26170PowerShell Elevation of Privilege Vulnerability
CVE-2026-26172Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-26173Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26174Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-26176Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability
CVE-2026-26177Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26178Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability
CVE-2026-26179Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26180Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26181Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-26182Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-26183Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
CVE-2026-26184Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-27907Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-27908Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability
CVE-2026-27909Windows Search Service Elevation of Privilege Vulnerability
CVE-2026-27910Windows Installer Elevation of Privilege Vulnerability
CVE-2026-27911Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-27912Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-27914Microsoft Management Console Elevation of Privilege Vulnerability
CVE-2026-27915Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27916Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27917Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability
CVE-2026-27918Windows Shell Elevation of Privilege Vulnerability
CVE-2026-27919Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27920Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-27921Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability
CVE-2026-27922Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-27923Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-27924Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-27926Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-27927Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-27929Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
CVE-2026-32068Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32069Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32070Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-32073Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-32074Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32075Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-32076Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-32077Windows UPnP Device Host Elevation of Privilege Vulnerability
CVE-2026-32078Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32080Windows WalletService Elevation of Privilege Vulnerability
CVE-2026-32082Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32083Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
CVE-2026-32086Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32087Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32089Windows Speech Brokered Api Elevation of Privilege Vulnerability
CVE-2026-32090Windows Speech Brokered Api Elevation of Privilege Vulnerability
CVE-2026-32091Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-32093Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32150Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-32152Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-32153Windows Speech Runtime Elevation of Privilege Vulnerability
CVE-2026-32154Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-32155Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-32158Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-32159Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-32160Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-32162Windows COM Elevation of Privilege Vulnerability
CVE-2026-32163Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32164Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32165Windows User Interface Core Elevation of Privilege Vulnerability
CVE-2026-32167SQL Server Elevation of Privilege Vulnerability
CVE-2026-32168Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2026-32171Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-32176SQL Server Elevation of Privilege Vulnerability
CVE-2026-32184Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability
CVE-2026-32192Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2026-32195Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-32216Windows Redirected Drive Buffering System Denial of Service Vulnerability
CVE-2026-32219Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-32222Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-32223Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability
CVE-2026-32224Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-33098Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
CVE-2026-33099Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-33100Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-33101Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2026-33104Win32k Elevation of Privilege Vulnerability
CVE-2026-33825Microsoft Defender Elevation of Privilege Vulnerability

Information Disclosure Vulnerabilities

CVECVE Title
CVE-2026-20806Windows COM Server Information Disclosure Vulnerability
CVE-2026-23653GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVE-2026-26155Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
CVE-2026-26169Windows Kernel Memory Information Disclosure Vulnerability
CVE-2026-27925Windows UPnP Device Host Information Disclosure Vulnerability
CVE-2026-27930Windows GDI Information Disclosure Vulnerability
CVE-2026-27931Windows GDI Information Disclosure Vulnerability
CVE-2026-32079Web Account Manager Information Disclosure Vulnerability
CVE-2026-32081Package Catalog Information Disclosure Vulnerability
CVE-2026-32084Windows Print Spooler Information Disclosure Vulnerability
CVE-2026-32085Remote Procedure Call Information Disclosure Vulnerability
CVE-2026-32151Windows Shell Information Disclosure Vulnerability
CVE-2026-32188Microsoft Excel Information Disclosure Vulnerability
CVE-2026-32212Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVE-2026-32214Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
CVE-2026-32215Windows Kernel Information Disclosure Vulnerability
CVE-2026-32217Windows Kernel Information Disclosure Vulnerability
CVE-2026-32218Windows Kernel Information Disclosure Vulnerability
CVE-2026-33103Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2026-33822Microsoft Word Information Disclosure Vulnerability

Remote Code Execution Vulnerabilities

CVECVE Title
CVE-2026-23657Microsoft Word Remote Code Execution Vulnerability
CVE-2026-26156Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-32149Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-32156Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-32157Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-32183Windows Snipping Tool Remote Code Execution Vulnerability
CVE-2026-32189Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32190Microsoft Office Remote Code Execution Vulnerability
CVE-2026-32197Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32198Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32199Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-32200Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-32221Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-33095Microsoft Word Remote Code Execution Vulnerability
CVE-2026-33114Microsoft Word Remote Code Execution Vulnerability
CVE-2026-33115Microsoft Word Remote Code Execution Vulnerability
CVE-2026-33120Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-33824Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
CVE-2026-33826Windows Active Directory Remote Code Execution Vulnerability
CVE-2026-33827Windows TCP/IP Remote Code Execution Vulnerability

Security Feature Bypass Vulnerabilities

CVECVE Title
CVE-2026-0390UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-20928Windows Recovery Environment Security Feature Bypass Vulnerability
CVE-2026-23670Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
CVE-2026-26143Microsoft PowerShell Security Feature Bypass Vulnerability
CVE-2026-26149Microsoft Power Apps Security Feature Bypass
CVE-2026-26175Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-27906Windows Hello Security Feature Bypass Vulnerability
CVE-2026-27913Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-27928Windows Hello Security Feature Bypass Vulnerability
CVE-2026-32088Windows Biometric Service Security Feature Bypass Vulnerability
CVE-2026-32220UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-32225Windows Shell Security Feature Bypass Vulnerability

 

Spoofing Vulnerabilities

CVECVE Title
CVE-2026-20945Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-26151Remote Desktop Spoofing Vulnerability
CVE-2026-32072Active Directory Spoofing Vulnerability
CVE-2026-32178.NET Spoofing Vulnerability
CVE-2026-32196Windows Admin Center Spoofing Vulnerability
CVE-2026-32201Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-32202Windows Shell Spoofing Vulnerability
CVE-2026-33829Windows Snipping Tool Spoofing Vulnerability

Tampering Vulnerability

CVECVE Title
CVE-2026-26154Windows Server Update Service (WSUS) Tampering Vulnerability

 

 

 

 

Share This Article

An Article By

Security News

The SonicWall Capture Labs Threat Research Team gathers, analyzes and vets cross-vector threat information from the SonicWall Capture Threat network, consisting of global devices and resources, including more than 1 million security sensors in nearly 200 countries and territories. The research team identifies, analyzes, and mitigates critical vulnerabilities and malware daily through in-depth research, which drives protection for all SonicWall customers. In addition to safeguarding networks globally, the research team supports the larger threat intelligence community by releasing weekly deep technical analyses of the most critical threats to small businesses, providing critical knowledge that defenders need to protect their networks.

Related Articles

  • Nested Deserialization to RCE in Adobe Commerce & Magento (CVE-2025-54236)
    Read More
  • Command Injection in HuangDou UTCMS (CVE-2024-9916) Enables RCE
    Read More