April Microsoft Patch Tuesday. A total of 167 vulnerabilities, about twice as many as in March. There is one vulnerability already being exploited in the wild:
🔻 Spoofing - Microsoft SharePoint Server (CVE-2026-32201). ZDI experts say "Spoofing bugs in SharePoint often manifest as cross-site scripting (XSS) bugs". "An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality), make changes to disclosed information (Integrity), but cannot limit access to the resource (Availability)". There is no info yet about how widely it is being used in attacks, but you should not delay patching, especially if SharePoint is exposed to the Internet.
[ Read the full overview on the avleonov.com website ]
@avleonovcom #Vulristics #PatchTuesday #Microsoft #Windows #SharePoint #MicrosoftDefender #ActiveDirectory #IKE #WindowsTCPIP #WindowsPushNotifications #RemoteDesktop #RPC #Winsock #IPv6 #IPSec #BlueHammer #ChaoticEclipse #Pwn2Own #NCSC
Post #1643
699
