WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) Microsoft Patches SharePoint Zero-Day and Other Significant Vulnerabilities in 2nd Largest Microsoft Patch Tuesday Ever
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partnerships
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Microsoft Patches SharePoint Zero-Day and Other Significant Vulnerabilities in 2nd Largest Microsoft Patch Tuesday Ever

TLP:CLEAR

Author: Chase Snow

Created: Thursday, April 16, 2026 - 13:27

Categories: Cybersecurity, Security Preparedness

Summary: Microsoft released their 2nd largest patch Tuesday updates ever in April, addressing 165 vulnerabilities. Of note, CVE-2026-32201 is a zero-day vulnerability in SharePoint and has been actively exploited in the wild. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The update also includes numerous vulnerabilities across Windows, Office, SQL Server, and other widely used enterprise products.

Analyst Note: Exploited vulnerabilities in widely deployed systems, particularly SharePoint and Active Directory, are frequently leveraged for initial access and lateral movement. Members are encouraged to prioritize patching internet-facing systems and review access controls for signs of exploitation.

Original Sources:

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201
  • https://www.microsoft.com/technet/security/advisory/968272.mspx

Additional Reading:

  • Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities
  • Microsoft security advisory – April 2026 monthly rollup (AV26-352)

Related WaterISAC PIRs: 6, 8, 10, 12

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar