WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) Microsoft Patches SharePoint Zero-Day and Other Significant Vulnerabilities in 2nd Largest Microsoft Patch Tuesday Ever
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Microsoft Patches SharePoint Zero-Day and Other Significant Vulnerabilities in 2nd Largest Microsoft Patch Tuesday Ever

TLP:CLEAR

Author: Chase Snow

Created: Thursday, April 16, 2026 - 13:27

Categories: Cybersecurity, Security Preparedness

Summary: Microsoft released their 2nd largest patch Tuesday updates ever in April, addressing 165 vulnerabilities. Of note, CVE-2026-32201 is a zero-day vulnerability in SharePoint and has been actively exploited in the wild. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The update also includes numerous vulnerabilities across Windows, Office, SQL Server, and other widely used enterprise products.

Analyst Note: Exploited vulnerabilities in widely deployed systems, particularly SharePoint and Active Directory, are frequently leveraged for initial access and lateral movement. Members are encouraged to prioritize patching internet-facing systems and review access controls for signs of exploitation.

Original Sources:

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201
  • https://www.microsoft.com/technet/security/advisory/968272.mspx

Additional Reading:

  • Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities
  • Microsoft security advisory – April 2026 monthly rollup (AV26-352)

Related WaterISAC PIRs: 6, 8, 10, 12

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 25, 2026)

Jun 25, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – June 25, 2026

Jun 25, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) CISA Guidance Helps Organizations Modernize Network Security with Zero Trust and SASE

Jun 25, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar