Microsoft shipped its April 2026 Patch Tuesday on April 14, 2026, fixing 163 vulnerabilities per the Belgian Cybersecurity Centre's advisory breakdown, with 8 rated critical and the remainder mostly important. Two of the flaws are zero-days — exploited in the wild before or without a fix available: CVE-2026-32201, a Microsoft SharePoint vulnerability, and CVE-2026-32202, a Windows Shell spoofing flaw. Both carry confirmed active-exploitation status in vendor and third-party reporting, which moves this month's release from routine to patch-now territory for anyone running the affected products.
What do we know about the zero-days?
Per the CCB advisory and Security Affairs' reporting, CVE-2026-32201 affects SharePoint and was actively exploited at release; CVE-2026-32202 is a Windows Shell spoofing vulnerability, likewise flagged as exploited zero-day. Beyond the two confirmed exploited flaws, the release includes roughly seven remote-code-execution issues among the critical set. SharePoint servers — often internet-facing in enterprises and stacked with sensitive content — make the more urgent of the pair, since SharePoint exploitation has repeatedly featured in ransomware initial access in past years. Expect both CVEs to join CISA's Known Exploited Vulnerabilities catalog if they have not already, which sets federal remediation deadlines and signals the same urgency for everyone else.
Who needs to act fastest?
Organizations running internet-facing SharePoint or Exchange farms, RDS hosts, and Windows servers open to untrusted networks go first. Workstations follow — Windows Shell flaws ultimately land on desktops. Home users have the simplest job and no excuse to delay: this month's cumulative update includes both zero-day fixes.
What should you do now?
- Windows home users: Settings > Windows Update > Check for updates, install, reboot. Done — the two zero-days are closed.
- Enterprises: treat CVE-2026-32201 as the priority — patch exposed SharePoint farms immediately, and check IIS and SharePoint logs for anomalous activity reaching back to at least early April, since zero-day exploitation predates the patch.
- Check the KEV catalog for both CVEs and note the remediation deadline if listed; where CISA has added them, the deadline is the ceiling, not the target.
- Communicate the reboot. These fixes require the monthly cumulative update and a restart — the single most common reason managed fleets show patched-but-vulnerable in audits.
February's Patch Tuesday had already set the year's tempo with six actively exploited zero-days in one release, per Redmond Magazine's and Rapid7's coverage, all later added to CISA's KEV catalog. April's pair continues the pattern: 2026 is shaping up as another year where the second Tuesday is not a formality but the main event, and the organizations that treat it that way — patching within days, not change-quarter — are structurally harder to breach.
For more context, read Microsoft's January 2026 Patch Tuesday lands; New York cyber officials urge immediate updates.
For more context, read cisa kev catalog march 2026.
For more context, read cisa emergency directive ed 26-03.

