📰 Full Story
Microsoft on April 14-15 released one of its largest Patch Tuesday updates, addressing roughly 165–167 vulnerabilities across Windows and related products and shipping cumulative Windows 11 packages (KB5083769/KB5082052). The rollout includes two zero-days: CVE-2026-32201, a SharePoint Server spoofing flaw that Microsoft says was actively exploited and has been added to CISA’s Known Exploited Vulnerabilities list; and CVE-2026-33825, an elevation-of-privilege defect in Microsoft Defender (publicly disclosed and linked to exploit code nicknamed “BlueHammer”). The cycle also patched multiple critical issues, including a near-9.8 CVSS remote-code-execution bug in the IKEv2 extension (CVE-2026-33824), numerous elevation-of-privilege flaws, Office and RDP-related bugs, and quality-of-life fixes for Windows 11.
Security firms warned administrators to prioritise emergency remediation, audit externally facing SharePoint instances, and deploy mitigations where immediate patching is not possible.







💬 Commentary