Skip to content
Noroxi

Patch Tuesday

April 2026

On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.

How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.

331 records · 4 KEV

Affecting your stack

This month's records that match the products and versions in your stack.

Sign in to see the ones matching your stack; records and notifications are free. →

Microsoft · April 14

163 · 4 KEV · 2 critical
  • CVE-2026-32201
    69This week

    Microsoft SharePoint Server Spoofing Vulnerability

    MediumCVSS 6.5KEVWeaponizedEPSS 43%

    microsoft · sharepoint serverApr 14, 2026

  • CVE-2026-33824
    69This week

    Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 2%

    microsoft · windows 10 1607Apr 14, 2026

  • CVE-2026-33825
    61This week

    Microsoft Defender Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 0%

    microsoft · defender antimalware platformApr 14, 2026

  • Windows Shell Spoofing Vulnerability

    MediumCVSS 4.3KEVWeaponizedEPSS 5%

    microsoft · windows 10 1607Apr 14, 2026

  • Microsoft Power Apps Desktop Client Spoofing Vulnerability

    CriticalCVSS 9.0No exploitEPSS 1%

    microsoft · power appsApr 14, 2026

  • Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · windows 10 1607Apr 14, 2026

  • Remote Desktop Client Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · remote desktop clientApr 14, 2026

  • Azure Logic Apps Elevation of Privilege Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · azure logic appsApr 14, 2026

  • Windows Shell Security Feature Bypass Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · windows 10 1607Apr 14, 2026

  • Microsoft SQL Server Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · sql server 2016Apr 14, 2026

  • Windows Hello Security Feature Bypass Vulnerability

    HighCVSS 8.7No exploitEPSS 1%

    microsoft · windows server 2016Apr 14, 2026

  • Windows COM Elevation of Privilege Vulnerability

    HighCVSS 8.4No exploitEPSS 0%

    microsoft · windows 10 1809Apr 14, 2026

+151 moreAll records of the vendor

Adobe · April 14

53 · 0 KEV · 6 critical
  • Adobe Connect | Deserialization of Untrusted Data (CWE-502)

    CriticalCVSS 9.6No exploitEPSS 2%

    adobe · connectApr 14, 2026

  • Adobe Connect | Deserialization of Untrusted Data (CWE-502)

    CriticalCVSS 9.3No exploitEPSS 2%

    adobe · connectApr 14, 2026

  • Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)

    CriticalCVSS 9.3No exploitEPSS 1%

    adobe · connectApr 14, 2026

  • Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)

    CriticalCVSS 9.3No exploitEPSS 1%

    adobe · connectApr 14, 2026

  • Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)

    CriticalCVSS 9.3No exploitEPSS 1%

    adobe · connectApr 14, 2026

  • ColdFusion | Improper Input Validation (CWE-20)

    CriticalCVSS 9.3No exploitEPSS 0%

    adobe · coldfusionApr 14, 2026

  • Adobe Framemaker | Untrusted Search Path (CWE-426)

    HighCVSS 8.6No exploitEPSS 0%

    adobe · framemakerApr 14, 2026

  • ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

    HighCVSS 8.6No exploitEPSS 1%

    adobe · coldfusionApr 14, 2026

  • Adobe Connect | Cross-site Scripting (XSS) (CWE-79)

    HighCVSS 8.7No exploitEPSS 1%

    adobe · connectApr 14, 2026

  • Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

    HighCVSS 8.6No exploitEPSS 1%

    adobe · acrobatApr 14, 2026

  • Photoshop Installer | CWE-427: Uncontrolled Search Path Element

    HighCVSS 8.6No exploitEPSS 0%

    adobe · photoshop installerApr 15, 2026

  • ColdFusion | Improper Input Validation (CWE-20)

    HighCVSS 8.4No exploitEPSS 0%

    adobe · coldfusionApr 14, 2026

+41 moreAll records of the vendor

SAP · April 14

0 · 0 KEV · 0 critical

No records in this window.

Siemens · April 14

5 · 0 KEV · 0 critical
  • A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3).

    HighCVSS 8.7No exploitEPSS 1%

    siemens · sinec nmsApr 14, 2026

  • A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8).

    HighCVSS 8.7No exploitEPSS 0%

    siemens · ruggedcom crossbow secure access manager primary (sam-p)Apr 14, 2026

  • A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC).

    MediumCVSS 6.9No exploitEPSS 0%

    siemens · sinec nmsApr 14, 2026

  • A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcente

    MediumCVSS 6.3No exploitEPSS 0%

    siemens · simcenter 3dApr 14, 2026

  • A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro

    MediumCVSS 5.1No exploitEPSS 0%

    siemens · industrial edge management pro v1Apr 14, 2026

All records of the vendor

Schneider Electric · April 14

8 · 0 KEV · 0 critical
  • CVE-2026-2399
    27Monitor

    CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files o

    MediumCVSS 6.9No exploitEPSS 0%

    schneider-electric · powerchute serial shutdownApr 14, 2026

  • CVE-2026-2402
    27Monitor

    CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the us

    MediumCVSS 6.9No exploitEPSS 0%

    schneider-electric · powerchute serial shutdownApr 14, 2026

  • CVE-2026-2404
    27Monitor

    CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters t

    MediumCVSS 6.9No exploitEPSS 0%

    schneider-electric · powerchute serial shutdownApr 14, 2026

  • CVE-2026-4832
    27Monitor

    CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unau

    MediumCVSS 6.9No exploitEPSS 0%

    schneider electric · easergy micom p14xApr 14, 2026

  • CVE-2026-2400
    21Monitor

    CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to re

    MediumCVSS 5.3No exploitEPSS 0%

    schneider-electric · powerchute serial shutdownApr 14, 2026

  • CVE-2026-2403
    21Monitor

    CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting lo

    MediumCVSS 5.3No exploitEPSS 0%

    schneider-electric · powerchute serial shutdownApr 14, 2026

  • CVE-2026-2405
    21Monitor

    CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of se

    MediumCVSS 5.3No exploitEPSS 0%

    schneider-electric · powerchute serial shutdownApr 14, 2026

  • CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when

    LowCVSS 2.4No exploitEPSS 0%

    schneider-electric · powerchute serial shutdownApr 14, 2026

All records of the vendor

Oracle (Critical Patch Update) · April 21

102 · 0 KEV · 5 critical
  • Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration).

    CriticalCVSS 9.8No exploitEPSS 1%

    oracle · advanced inbound telephonyApr 21, 2026

  • Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management).

    CriticalCVSS 9.1No exploitEPSS 0%

    oracle · enterprise manager base platformApr 21, 2026

  • Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).

    CriticalCVSS 9.1No exploitEPSS 0%

    oracle · identity manager connectorApr 21, 2026

  • Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).

    CriticalCVSS 9.1No exploitEPSS 0%

    oracle · identity manager connectorApr 21, 2026

  • Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).

    CriticalCVSS 9.1No exploitEPSS 0%

    oracle · identity manager connectorApr 21, 2026

  • Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core).

    HighCVSS 8.5No exploitEPSS 0%

    oracle · life sciences empirica signalApr 21, 2026

  • Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).

    HighCVSS 8.7No exploitEPSS 0%

    oracle · http serverApr 21, 2026

  • Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security).

    HighCVSS 8.1No exploitEPSS 0%

    oracle · peoplesoft enterprise peopletoolsApr 21, 2026

  • Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces).

    HighCVSS 7.8No exploitEPSS 0%

    oracle · application development frameworkApr 21, 2026

  • Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (com

    HighCVSS 7.5Proof of conceptEPSS 0%

    oracle · financial services analytical applications infrastructureApr 21, 2026

  • Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch).

    HighCVSS 7.6Proof of conceptEPSS 0%

    oracle · applications dbaApr 21, 2026

  • Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).

    HighCVSS 7.5Proof of conceptEPSS 1%

    oracle · jreApr 21, 2026

+90 moreAll records of the vendor