Zum Inhalt springen
Auto-CTI
Zurück zu allen Deep Dives
ZERO DAY INITIATIVE - BLOG

The April 2026 Security Update Review

KEV MEDIUM patch-tuesday elevation-of-privilege remote-code-execution windows

Strategische Zusammenfassung

CVE-2026-33825 ist eine Elevation-of-Privilege-Lücke in Microsoft Defender (CVSS 7.8) mit öffentlichem PoC; CVE-2026-32201 betrifft SharePoint Server Spoofing , beide Komponenten der Joel Traber AG-Infrastruktur erfordern sofortige Patch-Bewertung und Anwendung.

Relevanz für dich

This is a Patch Tuesday roundup covering Adobe and Microsoft security updates relevant to the company's tech stack (Microsoft Windows, Microsoft Defender, Adobe Acrobat Reader, Adobe Creative Cloud, SQL Server), but it is a background aggregation article without active threat campaign or nation-state implications.

Volltext

Zero Day Initiative — The April 2026 Security Update Review

April 14, 2026 | Dustin Childs

It’s time once again for Patch Tuesday, and this one is huge. We’ve also got multiple exploits in the wild, which adds another layer of urgency to this month’s release. Take a break from your regularly scheduled activities, and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:

**Adobe Patches for April 2026**

For April, Adobe released 12 bulletins addressing 61 unique CVEs in Adobe Acrobat Reader, InDesign, InCopy, FrameMaker, Connect, ColdFusion, Bridge, Photoshop, Illustrator, Experience Manager Screens, and the Adobe DNG SDK. Three of the Cold Fusion bugs came through the TrendAI ZDI program. For this month, I’m introducing an Adobe table as well. I’d love to get your feedback on whether this is helpful.

No new advisories are being released this month.

I will be in Berlin for the next Patch Tuesday, which will be May 12, and I’ll provide my full thoughts then on what will hopefully be a smaller release than this one. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!

[[email protected]](mailto:[email protected])

Find us on X

Find us on Mastodon

[[email protected]](mailto:[email protected])

Erwähnte CVEs

Risk Score

62
cvss base
65.00
kev bonus
20.00
epss bonus
10.00
poc bonus
15.00
raw before weight
110.00
industry weight
1.21
freshness factor
0.50
days old
47.00
vendor mismatch penalty
0.00
consensus penalty
-5.00

Pfad: operational

MITRE ATT&CK Mapping

5 TTPs
Recon
Resource Dev
Persistence
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Conf.: high medium low

Procedure-Details

Technik Tactic Procedure Conf. Quelle
T1068
Exploitation for Privilege Escalation
Privilege Escalation Multiple Elevation of Privilege vulnerabilities patched in April 2026, including bugs in Windows kernel, afd.sys, Desktop Windows Manager, SQL Server, and UPnP, allowing local attackers to gain SYSTEM-level, administrative, or SQL sysadmin privileges. high llm
T1203
Exploitation for Client Execution
Execution CVE in Adobe Acrobat Reader is actively being exploited in the wild, requiring urgent patching as it is under active attack at the time of release. high llm
T1211
Exploitation for Defense Evasion
Defense Evasion Several vulnerabilities in Windows Push Notifications, AFD for Winsock, Management Services, and User Interface Core allow sandbox escapes, enabling attackers to break out of restricted execution environments. high llm
T1190
Exploit Public-Facing Application
Initial Access ColdFusion vulnerabilities with a deployment priority of 1 are patched, indicating critical remotely exploitable bugs in the publicly accessible ColdFusion web application platform. medium llm
T1499
Endpoint Denial of Service
Impact A tampering vulnerability in WSUS allows an attacker to send specially crafted packets that affect service availability, resulting in Denial of Service; additionally, bugs in afd.sys and Desktop Windows Manager could crash affected systems. medium llm
ESC