Microsoft April/may 2026 Security Updates

Discussion in 'Software' started by NICK ADSL UK, Apr 14, 2026 at 1:39 PM.

Thread Status:
Not open for further replies.
  1. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    April 2026 Security Updates

    This release consists of the following 165 Microsoft CVEs:
    Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?

    Windows Boot Loader CVE-2026-0390
    Windows COM CVE-2026-20806
    Windows Recovery Environment Agent CVE-2026-20928
    Windows Management Services CVE-2026-20930
    Microsoft Office SharePoint CVE-2026-20945
    GitHub Copilot and Visual Studio Code CVE-2026-23653
    Microsoft Office Word CVE-2026-23657
    .NET Framework CVE-2026-23666
    Windows Virtualization-Based Security (VBS) Enclave CVE-2026-23670
    Applocker Filter Driver (applockerfltr.sys) CVE-2026-25184
    Microsoft PowerShell CVE-2026-26143
    Microsoft Power Apps CVE-2026-26149
    Windows Remote Desktop CVE-2026-26151
    Windows Cryptographic Services CVE-2026-26152
    Windows Encrypting File System (EFS) CVE-2026-26153
    Windows Server Update Service CVE-2026-26154
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2026-26155
    Role: Windows Hyper-V CVE-2026-26156
    Windows Remote Desktop Licensing Service CVE-2026-26159
    Windows Remote Desktop Licensing Service CVE-2026-26160
    Windows Sensor Data Service CVE-2026-26161
    Windows OLE CVE-2026-26162
    Windows Kernel CVE-2026-26163
    Windows Shell CVE-2026-26165
    Windows Shell CVE-2026-26166
    Windows Push Notifications CVE-2026-26167
    Windows Ancillary Function Driver for WinSock CVE-2026-26168
    Windows Kernel Memory CVE-2026-26169
    Microsoft PowerShell CVE-2026-26170
    .NET CVE-2026-26171
    Windows Push Notifications CVE-2026-26172
    Windows Ancillary Function Driver for WinSock CVE-2026-26173
    Windows Server Update Service CVE-2026-26174
    Windows Boot Manager CVE-2026-26175
    Windows Client Side Caching driver (csc.sys) CVE-2026-26176
    Windows Ancillary Function Driver for WinSock CVE-2026-26177
    Windows Advanced Rasterization Platform CVE-2026-26178
    Windows Kernel CVE-2026-26179
    Windows Kernel CVE-2026-26180
    Microsoft Brokering File System CVE-2026-26181
    Windows Ancillary Function Driver for WinSock CVE-2026-26182
    Windows RPC API CVE-2026-26183
    Windows Projected File System CVE-2026-26184
    Windows Hello CVE-2026-27906
    Windows Storage Spaces Controller CVE-2026-27907
    Windows TDI Translation Driver (tdx.sys) CVE-2026-27908
    Microsoft Windows Search Component CVE-2026-27909
    Windows Installer CVE-2026-27910
    Windows User Interface Core CVE-2026-27911
    Windows Kerberos CVE-2026-27912
    Windows BitLocker CVE-2026-27913
    Microsoft Management Console CVE-2026-27914
    Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27915
    Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27916
    Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) CVE-2026-27917
    Windows Shell CVE-2026-27918
    Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27919
    Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27920
    Windows TCP/IP CVE-2026-27921
    Windows Ancillary Function Driver for WinSock CVE-2026-27922
    Desktop Window Manager CVE-2026-27923
    Desktop Window Manager CVE-2026-27924
    Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27925
    Windows Cloud Files Mini Filter Driver CVE-2026-27926
    Windows Projected File System CVE-2026-27927
    Windows Hello CVE-2026-27928
    Windows LUAFV CVE-2026-27929
    Windows GDI CVE-2026-27930
    Windows GDI CVE-2026-27931
    Windows SSDP Service CVE-2026-32068
    Windows Projected File System CVE-2026-32069
    Windows Common Log File System Driver CVE-2026-32070
    Windows Local Security Authority Subsystem Service (LSASS) CVE-2026-32071
    Windows Active Directory CVE-2026-32072
    Windows Ancillary Function Driver for WinSock CVE-2026-32073
    Windows Projected File System CVE-2026-32074
    Windows Universal Plug and Play (UPnP) Device Host CVE-2026-32075
    Windows Storage Spaces Controller CVE-2026-32076
    Windows Universal Plug and Play (UPnP) Device Host CVE-2026-32077
    Windows Projected File System CVE-2026-32078
    Windows File Explorer CVE-2026-32079
    Windows WalletService CVE-2026-32080
    Windows File Explorer CVE-2026-32081
    Windows SSDP Service CVE-2026-32082
    Windows SSDP Service CVE-2026-32083
    Windows File Explorer CVE-2026-32084
    Windows Remote Procedure Call CVE-2026-32085
    Function Discovery Service (fdwsd.dll) CVE-2026-32086
    Function Discovery Service (fdwsd.dll) CVE-2026-32087
    Windows Biometric Service CVE-2026-32088
    Windows Speech Brokered Api CVE-2026-32089
    Windows Speech Brokered Api CVE-2026-32090
    Microsoft Brokering File System CVE-2026-32091
    Function Discovery Service (fdwsd.dll) CVE-2026-32093
    Role: Windows Hyper-V CVE-2026-32149
    Function Discovery Service (fdwsd.dll) CVE-2026-32150
    Windows Shell CVE-2026-32151
    Desktop Window Manager CVE-2026-32152
    Microsoft Windows Speech CVE-2026-32153
    Desktop Window Manager CVE-2026-32154
    Desktop Window Manager CVE-2026-32155
    Windows Universal Plug and Play (UPnP) Device Host CVE-2026-32156
    Remote Desktop Client CVE-2026-32157
    Windows Push Notifications CVE-2026-32158
    Windows Push Notifications CVE-2026-32159
    Windows Push Notifications CVE-2026-32160
    Windows COM CVE-2026-32162
    Windows User Interface Core CVE-2026-32163
    Windows User Interface Core CVE-2026-32164
    Windows User Interface Core CVE-2026-32165
    SQL Server CVE-2026-32167
    Azure Monitor Agent CVE-2026-32168
    Azure Logic Apps CVE-2026-32171
    SQL Server CVE-2026-32176 6.7
    .NET CVE-2026-32178
    Microsoft Windows CVE-2026-32181
    Windows Snipping Tool CVE-2026-32183
    Microsoft High Performance Compute Pack (HPC) CVE-2026-32184
    Microsoft Office Excel CVE-2026-32188
    Microsoft Office Excel CVE-2026-32189
    Microsoft Office CVE-2026-32190
    Azure Monitor Agent CVE-2026-32192
    Windows Kernel CVE-2026-32195
    Windows Admin Center CVE-2026-32196
    Microsoft Office Excel CVE-2026-32197
    Microsoft Office Excel CVE-2026-32198
    Microsoft Office Excel CVE-2026-32199
    Microsoft Office PowerPoint CVE-2026-32200
    Microsoft Office SharePoint CVE-2026-32201
    Windows Shell CVE-2026-32202
    .NET and Visual Studio CVE-2026-32203
    Universal Plug and Play (upnp.dll) CVE-2026-32212
    Universal Plug and Play (upnp.dll) CVE-2026-32214
    Windows Kernel CVE-2026-32215 5.5
    Windows Redirected Drive Buffering CVE-2026-32216
    Windows Kernel CVE-2026-32217
    Windows Kernel CVE-2026-32218
    Microsoft Brokering File System CVE-2026-32219
    Windows Virtualization-Based Security (VBS) Enclave CVE-2026-32220
    Microsoft Graphics Component CVE-2026-32221
    Windows Win32K - ICOMP CVE-2026-32222
    Windows USB Print Driver CVE-2026-32223
    Windows Server Update Service CVE-2026-32224
    Windows Shell CVE-2026-32225
    .NET Framework CVE-2026-32226
    Microsoft Office Word CVE-2026-33095
    Windows HTTP.sys CVE-2026-33096
    Windows Container Isolation FS Filter Driver CVE-2026-33098
    Windows Ancillary Function Driver for WinSock CVE-2026-33099
    Windows Ancillary Function Driver for WinSock CVE-2026-33100
    Windows Print Spooler Components CVE-2026-33101
    Microsoft Dynamics 365 (on-premises) CVE-2026-33103
    Windows Win32K - GRFX CVE-2026-33104
    Microsoft Office Word CVE-2026-33114
    Microsoft Office Word CVE-2026-33115
    .NET, .NET Framework, Visual Studio CVE-2026-33116
    Microsoft Edge (Chromium-based) CVE-2026-33118
    Microsoft Edge (Chromium-based) CVE-2026-33119
    SQL Server CVE-2026-33120
    Microsoft Office Word CVE-2026-33822
    Windows IKE Extension CVE-2026-33824
    Microsoft Defender CVE-2026-33825
    Windows Active Directory CVE-2026-33826
    Windows TCP/IP CVE-2026-33827
    Windows Snipping Tool CVE-2026-33829
     
  2. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    We are republishing 82 non-Microsoft CVEs:
    CNA Tag CVE FAQs? Workarounds? Mitigations?

    AMD Input-Output Memory Management Unit (IOMMU) CVE-2023-20585
    HackerOne Node.js CVE-2026-21637
    MITRE Windows Secure Boot CVE-2026-25250
    GitHub GitHub Repo: Git for Windows CVE-2026-32631
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5272
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5273
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5274
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5275
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5276
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5277
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5279
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5280
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5281
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5283
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5284
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5285
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5286
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5287
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5289
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5290
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5291
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5292
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5858
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5859
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5860
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5861
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5862
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5863
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5864
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5865
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5866
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5867
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5868
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5869
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5870
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5871
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5872
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5873
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5874
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5875
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5876
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5877
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5878
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5879
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5880
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5881
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5882
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5883
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5884
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5885
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5886
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5887
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5888
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5889
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5890
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5891
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5892
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5893
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5894
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5895
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5896
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5897
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5898
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5899
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5900
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5901
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5902
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5903
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5904
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5905
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5906
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5907
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5908
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5909
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5910
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5911
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5912
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5913
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5914
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5915
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5918
    Chrome Microsoft Edge (Chromium-based) CVE-2026-5919

    Security Update Guide Blog Posts
    Date Blog Post
    October 31, 2025 You asked, we delivered: Introducing new features for an improved security experience
    October 28, 2025 Understanding CVE-2025-55315: What CISOs, security engineers, and sysadmins should know
    October 22, 2025 Toward greater transparency: Introducing machine-readable Vulnerability Exploitability Xchange (VEX) for Azure Linux and beyond
    November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
    June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
    April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
    January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
    January 11, 2022 Coming Soon: New Security Update Guide Notification System
    February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
    January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
    December 8, 2020 Security Update Guide: Let’s keep the conversation going
    November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide

    Relevant Resources
    • The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
    • Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
    • Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
    • A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
    • In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
    • Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
    Known Issues
    You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.

    For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).

    KB Article Applies To
    5082060 Windows Server 2022 23H2
    5082063 Windows Server 2025
    5082142 Windows Server 2022
    Released: Apr 14, 2026

    April 2026 Security Updates - Release Notes - Security Update Guide - Microsoft
     
    Goddess Bastet and xrobwx71 like this.
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds