WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) Microsoft Patches SharePoint Zero-Day and Other Significant Vulnerabilities in 2nd Largest Microsoft Patch Tuesday Ever
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Microsoft Patches SharePoint Zero-Day and Other Significant Vulnerabilities in 2nd Largest Microsoft Patch Tuesday Ever

TLP:CLEAR

Author: Chase Snow

Created: Thursday, April 16, 2026 - 13:27

Categories: Cybersecurity, Security Preparedness

Summary: Microsoft released their 2nd largest patch Tuesday updates ever in April, addressing 165 vulnerabilities. Of note, CVE-2026-32201 is a zero-day vulnerability in SharePoint and has been actively exploited in the wild. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The update also includes numerous vulnerabilities across Windows, Office, SQL Server, and other widely used enterprise products.

Analyst Note: Exploited vulnerabilities in widely deployed systems, particularly SharePoint and Active Directory, are frequently leveraged for initial access and lateral movement. Members are encouraged to prioritize patching internet-facing systems and review access controls for signs of exploitation.

Original Sources:

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201
  • https://www.microsoft.com/technet/security/advisory/968272.mspx

Additional Reading:

  • Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities
  • Microsoft security advisory – April 2026 monthly rollup (AV26-352)

Related WaterISAC PIRs: 6, 8, 10, 12

Related Resources

Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) EPA to Conduct 2026 National Cyber Drill Focused on Operating Without Telecommunications and Internet Connectivity

Jun 4, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar