Patch Tuesday April 2026: what Microsoft shipped
Microsoft published its security updates on Tuesday, 14 April 2026.
On the day, the briefing reads Microsoft's advisories and this page lists what carried a flag. It stays here afterwards as the record.
Which flaws were flagged?
2 flagged by Microsoft as exploited at release.
One flagged by Microsoft as publicly disclosed.
3 are in the CISA KEV catalog.
- CVE-2026-32201 Microsoft SharePoint Server Spoofing Vulnerability Exploited at release · In KEV
- CVE-2026-32202 Windows Shell Spoofing Vulnerability Exploited at release · In KEV
- CVE-2026-33825 Microsoft Defender Elevation of Privilege Vulnerability Publicly disclosed · In KEV
What PlainSec published
What the last cycles held
March 2026: 2 flagged.
February 2026: 6 flagged.
We hold 15 CVEs from Microsoft's 2026-Apr document. That is what our records reach, not the size of the release: it grows for weeks after the day.