April 2026 Security Updates
This release consists of the following 165 Microsoft CVEs:
Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
Windows Boot Loader CVE-2026-0390
Windows COM CVE-2026-20806
Windows Recovery Environment Agent CVE-2026-20928
Windows Management Services CVE-2026-20930
Microsoft Office SharePoint CVE-2026-20945
GitHub Copilot and Visual Studio Code CVE-2026-23653
Microsoft Office Word CVE-2026-23657
.NET Framework CVE-2026-23666
Windows Virtualization-Based Security (VBS) Enclave CVE-2026-23670
Applocker Filter Driver (applockerfltr.sys) CVE-2026-25184
Microsoft PowerShell CVE-2026-26143
Microsoft Power Apps CVE-2026-26149
Windows Remote Desktop CVE-2026-26151
Windows Cryptographic Services CVE-2026-26152
Windows Encrypting File System (EFS) CVE-2026-26153
Windows Server Update Service CVE-2026-26154
Windows Local Security Authority Subsystem Service (LSASS) CVE-2026-26155
Role: Windows Hyper-V CVE-2026-26156
Windows Remote Desktop Licensing Service CVE-2026-26159
Windows Remote Desktop Licensing Service CVE-2026-26160
Windows Sensor Data Service CVE-2026-26161
Windows OLE CVE-2026-26162
Windows Kernel CVE-2026-26163
Windows Shell CVE-2026-26165
Windows Shell CVE-2026-26166
Windows Push Notifications CVE-2026-26167
Windows Ancillary Function Driver for WinSock CVE-2026-26168
Windows Kernel Memory CVE-2026-26169
Microsoft PowerShell CVE-2026-26170
.NET CVE-2026-26171
Windows Push Notifications CVE-2026-26172
Windows Ancillary Function Driver for WinSock CVE-2026-26173
Windows Server Update Service CVE-2026-26174
Windows Boot Manager CVE-2026-26175
Windows Client Side Caching driver (csc.sys) CVE-2026-26176
Windows Ancillary Function Driver for WinSock CVE-2026-26177
Windows Advanced Rasterization Platform CVE-2026-26178
Windows Kernel CVE-2026-26179
Windows Kernel CVE-2026-26180
Microsoft Brokering File System CVE-2026-26181
Windows Ancillary Function Driver for WinSock CVE-2026-26182
Windows RPC API CVE-2026-26183
Windows Projected File System CVE-2026-26184
Windows Hello CVE-2026-27906
Windows Storage Spaces Controller CVE-2026-27907
Windows TDI Translation Driver (tdx.sys) CVE-2026-27908
Microsoft Windows Search Component CVE-2026-27909
Windows Installer CVE-2026-27910
Windows User Interface Core CVE-2026-27911
Windows Kerberos CVE-2026-27912
Windows BitLocker CVE-2026-27913
Microsoft Management Console CVE-2026-27914
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27915
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27916
Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) CVE-2026-27917
Windows Shell CVE-2026-27918
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27919
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27920
Windows TCP/IP CVE-2026-27921
Windows Ancillary Function Driver for WinSock CVE-2026-27922
Desktop Window Manager CVE-2026-27923
Desktop Window Manager CVE-2026-27924
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27925
Windows Cloud Files Mini Filter Driver CVE-2026-27926
Windows Projected File System CVE-2026-27927
Windows Hello CVE-2026-27928
Windows LUAFV CVE-2026-27929
Windows GDI CVE-2026-27930
Windows GDI CVE-2026-27931
Windows SSDP Service CVE-2026-32068
Windows Projected File System CVE-2026-32069
Windows Common Log File System Driver CVE-2026-32070
Windows Local Security Authority Subsystem Service (LSASS) CVE-2026-32071
Windows Active Directory CVE-2026-32072
Windows Ancillary Function Driver for WinSock CVE-2026-32073
Windows Projected File System CVE-2026-32074
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-32075
Windows Storage Spaces Controller CVE-2026-32076
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-32077
Windows Projected File System CVE-2026-32078
Windows File Explorer CVE-2026-32079
Windows WalletService CVE-2026-32080
Windows File Explorer CVE-2026-32081
Windows SSDP Service CVE-2026-32082
Windows SSDP Service CVE-2026-32083
Windows File Explorer CVE-2026-32084
Windows Remote Procedure Call CVE-2026-32085
Function Discovery Service (fdwsd.dll) CVE-2026-32086
Function Discovery Service (fdwsd.dll) CVE-2026-32087
Windows Biometric Service CVE-2026-32088
Windows Speech Brokered Api CVE-2026-32089
Windows Speech Brokered Api CVE-2026-32090
Microsoft Brokering File System CVE-2026-32091
Function Discovery Service (fdwsd.dll) CVE-2026-32093
Role: Windows Hyper-V CVE-2026-32149
Function Discovery Service (fdwsd.dll) CVE-2026-32150
Windows Shell CVE-2026-32151
Desktop Window Manager CVE-2026-32152
Microsoft Windows Speech CVE-2026-32153
Desktop Window Manager CVE-2026-32154
Desktop Window Manager CVE-2026-32155
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-32156
Remote Desktop Client CVE-2026-32157
Windows Push Notifications CVE-2026-32158
Windows Push Notifications CVE-2026-32159
Windows Push Notifications CVE-2026-32160
Windows COM CVE-2026-32162
Windows User Interface Core CVE-2026-32163
Windows User Interface Core CVE-2026-32164
Windows User Interface Core CVE-2026-32165
SQL Server CVE-2026-32167
Azure Monitor Agent CVE-2026-32168
Azure Logic Apps CVE-2026-32171
SQL Server CVE-2026-32176 6.7
.NET CVE-2026-32178
Microsoft Windows CVE-2026-32181
Windows Snipping Tool CVE-2026-32183
Microsoft High Performance Compute Pack (HPC) CVE-2026-32184
Microsoft Office Excel CVE-2026-32188
Microsoft Office Excel CVE-2026-32189
Microsoft Office CVE-2026-32190
Azure Monitor Agent CVE-2026-32192
Windows Kernel CVE-2026-32195
Windows Admin Center CVE-2026-32196
Microsoft Office Excel CVE-2026-32197
Microsoft Office Excel CVE-2026-32198
Microsoft Office Excel CVE-2026-32199
Microsoft Office PowerPoint CVE-2026-32200
Microsoft Office SharePoint CVE-2026-32201
Windows Shell CVE-2026-32202
.NET and Visual Studio CVE-2026-32203
Universal Plug and Play (upnp.dll) CVE-2026-32212
Universal Plug and Play (upnp.dll) CVE-2026-32214
Windows Kernel CVE-2026-32215 5.5
Windows Redirected Drive Buffering CVE-2026-32216
Windows Kernel CVE-2026-32217
Windows Kernel CVE-2026-32218
Microsoft Brokering File System CVE-2026-32219
Windows Virtualization-Based Security (VBS) Enclave CVE-2026-32220
Microsoft Graphics Component CVE-2026-32221
Windows Win32K - ICOMP CVE-2026-32222
Windows USB Print Driver CVE-2026-32223
Windows Server Update Service CVE-2026-32224
Windows Shell CVE-2026-32225
.NET Framework CVE-2026-32226
Microsoft Office Word CVE-2026-33095
Windows HTTP.sys CVE-2026-33096
Windows Container Isolation FS Filter Driver CVE-2026-33098
Windows Ancillary Function Driver for WinSock CVE-2026-33099
Windows Ancillary Function Driver for WinSock CVE-2026-33100
Windows Print Spooler Components CVE-2026-33101
Microsoft Dynamics 365 (on-premises) CVE-2026-33103
Windows Win32K - GRFX CVE-2026-33104
Microsoft Office Word CVE-2026-33114
Microsoft Office Word CVE-2026-33115
.NET, .NET Framework, Visual Studio CVE-2026-33116
Microsoft Edge (Chromium-based) CVE-2026-33118
Microsoft Edge (Chromium-based) CVE-2026-33119
SQL Server CVE-2026-33120
Microsoft Office Word CVE-2026-33822
Windows IKE Extension CVE-2026-33824
Microsoft Defender CVE-2026-33825
Windows Active Directory CVE-2026-33826
Windows TCP/IP CVE-2026-33827
Windows Snipping Tool CVE-2026-33829
We are republishing 82 non-Microsoft CVEs:
CNA Tag CVE FAQs? Workarounds? Mitigations?
AMD Input-Output Memory Management Unit (IOMMU) CVE-2023-20585 No No No
HackerOne Node.js CVE-2026-21637 No No No
MITRE Windows Secure Boot CVE-2026-25250
GitHub GitHub Repo: Git for Windows CVE-2026-32631
Chrome Microsoft Edge (Chromium-based) CVE-2026-5272
Chrome Microsoft Edge (Chromium-based) CVE-2026-5273
Chrome Microsoft Edge (Chromium-based) CVE-2026-5274
Chrome Microsoft Edge (Chromium-based) CVE-2026-5275
Chrome Microsoft Edge (Chromium-based) CVE-2026-5276
Chrome Microsoft Edge (Chromium-based) CVE-2026-5277
Chrome Microsoft Edge (Chromium-based) CVE-2026-5279
Chrome Microsoft Edge (Chromium-based) CVE-2026-5280
Chrome Microsoft Edge (Chromium-based) CVE-2026-5281
Chrome Microsoft Edge (Chromium-based) CVE-2026-5283
Chrome Microsoft Edge (Chromium-based) CVE-2026-5284
Chrome Microsoft Edge (Chromium-based) CVE-2026-5285
Chrome Microsoft Edge (Chromium-based) CVE-2026-5286
Chrome Microsoft Edge (Chromium-based) CVE-2026-5287
Chrome Microsoft Edge (Chromium-based) CVE-2026-5289
Chrome Microsoft Edge (Chromium-based) CVE-2026-5290
Chrome Microsoft Edge (Chromium-based) CVE-2026-5291
Chrome Microsoft Edge (Chromium-based) CVE-2026-5292
Chrome Microsoft Edge (Chromium-based) CVE-2026-5858
Chrome Microsoft Edge (Chromium-based) CVE-2026-5859
Chrome Microsoft Edge (Chromium-based) CVE-2026-5860
Chrome Microsoft Edge (Chromium-based) CVE-2026-5861
Chrome Microsoft Edge (Chromium-based) CVE-2026-5862
Chrome Microsoft Edge (Chromium-based) CVE-2026-5863
Chrome Microsoft Edge (Chromium-based) CVE-2026-5864
Chrome Microsoft Edge (Chromium-based) CVE-2026-5865
Chrome Microsoft Edge (Chromium-based) CVE-2026-5866
Chrome Microsoft Edge (Chromium-based) CVE-2026-5867
Chrome Microsoft Edge (Chromium-based) CVE-2026-5868
Chrome Microsoft Edge (Chromium-based) CVE-2026-5869
Chrome Microsoft Edge (Chromium-based) CVE-2026-5870
Chrome Microsoft Edge (Chromium-based) CVE-2026-5871
Chrome Microsoft Edge (Chromium-based) CVE-2026-5872
Chrome Microsoft Edge (Chromium-based) CVE-2026-5873
Chrome Microsoft Edge (Chromium-based) CVE-2026-5874
Chrome Microsoft Edge (Chromium-based) CVE-2026-5875
Chrome Microsoft Edge (Chromium-based) CVE-2026-5876
Chrome Microsoft Edge (Chromium-based) CVE-2026-5877
Chrome Microsoft Edge (Chromium-based) CVE-2026-5878
Chrome Microsoft Edge (Chromium-based) CVE-2026-5879
Chrome Microsoft Edge (Chromium-based) CVE-2026-5880
Chrome Microsoft Edge (Chromium-based) CVE-2026-5881
Chrome Microsoft Edge (Chromium-based) CVE-2026-5882
Chrome Microsoft Edge (Chromium-based) CVE-2026-5883
Chrome Microsoft Edge (Chromium-based) CVE-2026-5884
Chrome Microsoft Edge (Chromium-based) CVE-2026-5885
Chrome Microsoft Edge (Chromium-based) CVE-2026-5886
Chrome Microsoft Edge (Chromium-based) CVE-2026-5887
Chrome Microsoft Edge (Chromium-based) CVE-2026-5888
Chrome Microsoft Edge (Chromium-based) CVE-2026-5889
Chrome Microsoft Edge (Chromium-based) CVE-2026-5890
Chrome Microsoft Edge (Chromium-based) CVE-2026-5891
Chrome Microsoft Edge (Chromium-based) CVE-2026-5892
Chrome Microsoft Edge (Chromium-based) CVE-2026-5893
Chrome Microsoft Edge (Chromium-based) CVE-2026-5894
Chrome Microsoft Edge (Chromium-based) CVE-2026-5895
Chrome Microsoft Edge (Chromium-based) CVE-2026-5896
Chrome Microsoft Edge (Chromium-based) CVE-2026-5897
Chrome Microsoft Edge (Chromium-based) CVE-2026-5898
Chrome Microsoft Edge (Chromium-based) CVE-2026-5899
Chrome Microsoft Edge (Chromium-based) CVE-2026-5900
Chrome Microsoft Edge (Chromium-based) CVE-2026-5901
Chrome Microsoft Edge (Chromium-based) CVE-2026-5902
Chrome Microsoft Edge (Chromium-based) CVE-2026-5903
Chrome Microsoft Edge (Chromium-based) CVE-2026-5904
Chrome Microsoft Edge (Chromium-based) CVE-2026-5905
Chrome Microsoft Edge (Chromium-based) CVE-2026-5906
Chrome Microsoft Edge (Chromium-based) CVE-2026-5907
Chrome Microsoft Edge (Chromium-based) CVE-2026-5908
Chrome Microsoft Edge (Chromium-based) CVE-2026-5909
Chrome Microsoft Edge (Chromium-based) CVE-2026-5910
Chrome Microsoft Edge (Chromium-based) CVE-2026-5911
Chrome Microsoft Edge (Chromium-based) CVE-2026-5912
Chrome Microsoft Edge (Chromium-based) CVE-2026-5913
Chrome Microsoft Edge (Chromium-based) CVE-2026-5914
Chrome Microsoft Edge (Chromium-based) CVE-2026-5915
Chrome Microsoft Edge (Chromium-based) CVE-2026-5918
Chrome Microsoft Edge (Chromium-based) CVE-2026-5919
Security Update Guide Blog Posts
Date Blog Post
October 31, 2025 You asked, we delivered: Introducing new features for an improved security experience
October 28, 2025 Understanding CVE-2025-55315: What CISOs, security engineers, and sysadmins should know
October 22, 2025 Toward greater transparency: Introducing machine-readable Vulnerability Exploitability Xchange (VEX) for Azure Linux and beyond
November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
January 11, 2022 Coming Soon: New Security Update Guide Notification System
February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
December 8, 2020 Security Update Guide: Let’s keep the conversation going
November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide
Relevant Resources
You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.
For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).
KB Article Applies To
5082060 Windows Server 2022 23H2
5082063 Windows Server 2025
5082142 Windows Server 2022
Released: Apr 14, 2026
April 2026 Security Updates - Release Notes - Security Update Guide - Microsoft
This release consists of the following 165 Microsoft CVEs:
Tag CVE Base Score CVSS Vector Exploitability FAQs? Workarounds? Mitigations?
Windows Boot Loader CVE-2026-0390
Windows COM CVE-2026-20806
Windows Recovery Environment Agent CVE-2026-20928
Windows Management Services CVE-2026-20930
Microsoft Office SharePoint CVE-2026-20945
GitHub Copilot and Visual Studio Code CVE-2026-23653
Microsoft Office Word CVE-2026-23657
.NET Framework CVE-2026-23666
Windows Virtualization-Based Security (VBS) Enclave CVE-2026-23670
Applocker Filter Driver (applockerfltr.sys) CVE-2026-25184
Microsoft PowerShell CVE-2026-26143
Microsoft Power Apps CVE-2026-26149
Windows Remote Desktop CVE-2026-26151
Windows Cryptographic Services CVE-2026-26152
Windows Encrypting File System (EFS) CVE-2026-26153
Windows Server Update Service CVE-2026-26154
Windows Local Security Authority Subsystem Service (LSASS) CVE-2026-26155
Role: Windows Hyper-V CVE-2026-26156
Windows Remote Desktop Licensing Service CVE-2026-26159
Windows Remote Desktop Licensing Service CVE-2026-26160
Windows Sensor Data Service CVE-2026-26161
Windows OLE CVE-2026-26162
Windows Kernel CVE-2026-26163
Windows Shell CVE-2026-26165
Windows Shell CVE-2026-26166
Windows Push Notifications CVE-2026-26167
Windows Ancillary Function Driver for WinSock CVE-2026-26168
Windows Kernel Memory CVE-2026-26169
Microsoft PowerShell CVE-2026-26170
.NET CVE-2026-26171
Windows Push Notifications CVE-2026-26172
Windows Ancillary Function Driver for WinSock CVE-2026-26173
Windows Server Update Service CVE-2026-26174
Windows Boot Manager CVE-2026-26175
Windows Client Side Caching driver (csc.sys) CVE-2026-26176
Windows Ancillary Function Driver for WinSock CVE-2026-26177
Windows Advanced Rasterization Platform CVE-2026-26178
Windows Kernel CVE-2026-26179
Windows Kernel CVE-2026-26180
Microsoft Brokering File System CVE-2026-26181
Windows Ancillary Function Driver for WinSock CVE-2026-26182
Windows RPC API CVE-2026-26183
Windows Projected File System CVE-2026-26184
Windows Hello CVE-2026-27906
Windows Storage Spaces Controller CVE-2026-27907
Windows TDI Translation Driver (tdx.sys) CVE-2026-27908
Microsoft Windows Search Component CVE-2026-27909
Windows Installer CVE-2026-27910
Windows User Interface Core CVE-2026-27911
Windows Kerberos CVE-2026-27912
Windows BitLocker CVE-2026-27913
Microsoft Management Console CVE-2026-27914
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27915
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27916
Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) CVE-2026-27917
Windows Shell CVE-2026-27918
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27919
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27920
Windows TCP/IP CVE-2026-27921
Windows Ancillary Function Driver for WinSock CVE-2026-27922
Desktop Window Manager CVE-2026-27923
Desktop Window Manager CVE-2026-27924
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-27925
Windows Cloud Files Mini Filter Driver CVE-2026-27926
Windows Projected File System CVE-2026-27927
Windows Hello CVE-2026-27928
Windows LUAFV CVE-2026-27929
Windows GDI CVE-2026-27930
Windows GDI CVE-2026-27931
Windows SSDP Service CVE-2026-32068
Windows Projected File System CVE-2026-32069
Windows Common Log File System Driver CVE-2026-32070
Windows Local Security Authority Subsystem Service (LSASS) CVE-2026-32071
Windows Active Directory CVE-2026-32072
Windows Ancillary Function Driver for WinSock CVE-2026-32073
Windows Projected File System CVE-2026-32074
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-32075
Windows Storage Spaces Controller CVE-2026-32076
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-32077
Windows Projected File System CVE-2026-32078
Windows File Explorer CVE-2026-32079
Windows WalletService CVE-2026-32080
Windows File Explorer CVE-2026-32081
Windows SSDP Service CVE-2026-32082
Windows SSDP Service CVE-2026-32083
Windows File Explorer CVE-2026-32084
Windows Remote Procedure Call CVE-2026-32085
Function Discovery Service (fdwsd.dll) CVE-2026-32086
Function Discovery Service (fdwsd.dll) CVE-2026-32087
Windows Biometric Service CVE-2026-32088
Windows Speech Brokered Api CVE-2026-32089
Windows Speech Brokered Api CVE-2026-32090
Microsoft Brokering File System CVE-2026-32091
Function Discovery Service (fdwsd.dll) CVE-2026-32093
Role: Windows Hyper-V CVE-2026-32149
Function Discovery Service (fdwsd.dll) CVE-2026-32150
Windows Shell CVE-2026-32151
Desktop Window Manager CVE-2026-32152
Microsoft Windows Speech CVE-2026-32153
Desktop Window Manager CVE-2026-32154
Desktop Window Manager CVE-2026-32155
Windows Universal Plug and Play (UPnP) Device Host CVE-2026-32156
Remote Desktop Client CVE-2026-32157
Windows Push Notifications CVE-2026-32158
Windows Push Notifications CVE-2026-32159
Windows Push Notifications CVE-2026-32160
Windows COM CVE-2026-32162
Windows User Interface Core CVE-2026-32163
Windows User Interface Core CVE-2026-32164
Windows User Interface Core CVE-2026-32165
SQL Server CVE-2026-32167
Azure Monitor Agent CVE-2026-32168
Azure Logic Apps CVE-2026-32171
SQL Server CVE-2026-32176 6.7
.NET CVE-2026-32178
Microsoft Windows CVE-2026-32181
Windows Snipping Tool CVE-2026-32183
Microsoft High Performance Compute Pack (HPC) CVE-2026-32184
Microsoft Office Excel CVE-2026-32188
Microsoft Office Excel CVE-2026-32189
Microsoft Office CVE-2026-32190
Azure Monitor Agent CVE-2026-32192
Windows Kernel CVE-2026-32195
Windows Admin Center CVE-2026-32196
Microsoft Office Excel CVE-2026-32197
Microsoft Office Excel CVE-2026-32198
Microsoft Office Excel CVE-2026-32199
Microsoft Office PowerPoint CVE-2026-32200
Microsoft Office SharePoint CVE-2026-32201
Windows Shell CVE-2026-32202
.NET and Visual Studio CVE-2026-32203
Universal Plug and Play (upnp.dll) CVE-2026-32212
Universal Plug and Play (upnp.dll) CVE-2026-32214
Windows Kernel CVE-2026-32215 5.5
Windows Redirected Drive Buffering CVE-2026-32216
Windows Kernel CVE-2026-32217
Windows Kernel CVE-2026-32218
Microsoft Brokering File System CVE-2026-32219
Windows Virtualization-Based Security (VBS) Enclave CVE-2026-32220
Microsoft Graphics Component CVE-2026-32221
Windows Win32K - ICOMP CVE-2026-32222
Windows USB Print Driver CVE-2026-32223
Windows Server Update Service CVE-2026-32224
Windows Shell CVE-2026-32225
.NET Framework CVE-2026-32226
Microsoft Office Word CVE-2026-33095
Windows HTTP.sys CVE-2026-33096
Windows Container Isolation FS Filter Driver CVE-2026-33098
Windows Ancillary Function Driver for WinSock CVE-2026-33099
Windows Ancillary Function Driver for WinSock CVE-2026-33100
Windows Print Spooler Components CVE-2026-33101
Microsoft Dynamics 365 (on-premises) CVE-2026-33103
Windows Win32K - GRFX CVE-2026-33104
Microsoft Office Word CVE-2026-33114
Microsoft Office Word CVE-2026-33115
.NET, .NET Framework, Visual Studio CVE-2026-33116
Microsoft Edge (Chromium-based) CVE-2026-33118
Microsoft Edge (Chromium-based) CVE-2026-33119
SQL Server CVE-2026-33120
Microsoft Office Word CVE-2026-33822
Windows IKE Extension CVE-2026-33824
Microsoft Defender CVE-2026-33825
Windows Active Directory CVE-2026-33826
Windows TCP/IP CVE-2026-33827
Windows Snipping Tool CVE-2026-33829
We are republishing 82 non-Microsoft CVEs:
CNA Tag CVE FAQs? Workarounds? Mitigations?
AMD Input-Output Memory Management Unit (IOMMU) CVE-2023-20585 No No No
HackerOne Node.js CVE-2026-21637 No No No
MITRE Windows Secure Boot CVE-2026-25250
GitHub GitHub Repo: Git for Windows CVE-2026-32631
Chrome Microsoft Edge (Chromium-based) CVE-2026-5272
Chrome Microsoft Edge (Chromium-based) CVE-2026-5273
Chrome Microsoft Edge (Chromium-based) CVE-2026-5274
Chrome Microsoft Edge (Chromium-based) CVE-2026-5275
Chrome Microsoft Edge (Chromium-based) CVE-2026-5276
Chrome Microsoft Edge (Chromium-based) CVE-2026-5277
Chrome Microsoft Edge (Chromium-based) CVE-2026-5279
Chrome Microsoft Edge (Chromium-based) CVE-2026-5280
Chrome Microsoft Edge (Chromium-based) CVE-2026-5281
Chrome Microsoft Edge (Chromium-based) CVE-2026-5283
Chrome Microsoft Edge (Chromium-based) CVE-2026-5284
Chrome Microsoft Edge (Chromium-based) CVE-2026-5285
Chrome Microsoft Edge (Chromium-based) CVE-2026-5286
Chrome Microsoft Edge (Chromium-based) CVE-2026-5287
Chrome Microsoft Edge (Chromium-based) CVE-2026-5289
Chrome Microsoft Edge (Chromium-based) CVE-2026-5290
Chrome Microsoft Edge (Chromium-based) CVE-2026-5291
Chrome Microsoft Edge (Chromium-based) CVE-2026-5292
Chrome Microsoft Edge (Chromium-based) CVE-2026-5858
Chrome Microsoft Edge (Chromium-based) CVE-2026-5859
Chrome Microsoft Edge (Chromium-based) CVE-2026-5860
Chrome Microsoft Edge (Chromium-based) CVE-2026-5861
Chrome Microsoft Edge (Chromium-based) CVE-2026-5862
Chrome Microsoft Edge (Chromium-based) CVE-2026-5863
Chrome Microsoft Edge (Chromium-based) CVE-2026-5864
Chrome Microsoft Edge (Chromium-based) CVE-2026-5865
Chrome Microsoft Edge (Chromium-based) CVE-2026-5866
Chrome Microsoft Edge (Chromium-based) CVE-2026-5867
Chrome Microsoft Edge (Chromium-based) CVE-2026-5868
Chrome Microsoft Edge (Chromium-based) CVE-2026-5869
Chrome Microsoft Edge (Chromium-based) CVE-2026-5870
Chrome Microsoft Edge (Chromium-based) CVE-2026-5871
Chrome Microsoft Edge (Chromium-based) CVE-2026-5872
Chrome Microsoft Edge (Chromium-based) CVE-2026-5873
Chrome Microsoft Edge (Chromium-based) CVE-2026-5874
Chrome Microsoft Edge (Chromium-based) CVE-2026-5875
Chrome Microsoft Edge (Chromium-based) CVE-2026-5876
Chrome Microsoft Edge (Chromium-based) CVE-2026-5877
Chrome Microsoft Edge (Chromium-based) CVE-2026-5878
Chrome Microsoft Edge (Chromium-based) CVE-2026-5879
Chrome Microsoft Edge (Chromium-based) CVE-2026-5880
Chrome Microsoft Edge (Chromium-based) CVE-2026-5881
Chrome Microsoft Edge (Chromium-based) CVE-2026-5882
Chrome Microsoft Edge (Chromium-based) CVE-2026-5883
Chrome Microsoft Edge (Chromium-based) CVE-2026-5884
Chrome Microsoft Edge (Chromium-based) CVE-2026-5885
Chrome Microsoft Edge (Chromium-based) CVE-2026-5886
Chrome Microsoft Edge (Chromium-based) CVE-2026-5887
Chrome Microsoft Edge (Chromium-based) CVE-2026-5888
Chrome Microsoft Edge (Chromium-based) CVE-2026-5889
Chrome Microsoft Edge (Chromium-based) CVE-2026-5890
Chrome Microsoft Edge (Chromium-based) CVE-2026-5891
Chrome Microsoft Edge (Chromium-based) CVE-2026-5892
Chrome Microsoft Edge (Chromium-based) CVE-2026-5893
Chrome Microsoft Edge (Chromium-based) CVE-2026-5894
Chrome Microsoft Edge (Chromium-based) CVE-2026-5895
Chrome Microsoft Edge (Chromium-based) CVE-2026-5896
Chrome Microsoft Edge (Chromium-based) CVE-2026-5897
Chrome Microsoft Edge (Chromium-based) CVE-2026-5898
Chrome Microsoft Edge (Chromium-based) CVE-2026-5899
Chrome Microsoft Edge (Chromium-based) CVE-2026-5900
Chrome Microsoft Edge (Chromium-based) CVE-2026-5901
Chrome Microsoft Edge (Chromium-based) CVE-2026-5902
Chrome Microsoft Edge (Chromium-based) CVE-2026-5903
Chrome Microsoft Edge (Chromium-based) CVE-2026-5904
Chrome Microsoft Edge (Chromium-based) CVE-2026-5905
Chrome Microsoft Edge (Chromium-based) CVE-2026-5906
Chrome Microsoft Edge (Chromium-based) CVE-2026-5907
Chrome Microsoft Edge (Chromium-based) CVE-2026-5908
Chrome Microsoft Edge (Chromium-based) CVE-2026-5909
Chrome Microsoft Edge (Chromium-based) CVE-2026-5910
Chrome Microsoft Edge (Chromium-based) CVE-2026-5911
Chrome Microsoft Edge (Chromium-based) CVE-2026-5912
Chrome Microsoft Edge (Chromium-based) CVE-2026-5913
Chrome Microsoft Edge (Chromium-based) CVE-2026-5914
Chrome Microsoft Edge (Chromium-based) CVE-2026-5915
Chrome Microsoft Edge (Chromium-based) CVE-2026-5918
Chrome Microsoft Edge (Chromium-based) CVE-2026-5919
Security Update Guide Blog Posts
Date Blog Post
October 31, 2025 You asked, we delivered: Introducing new features for an improved security experience
October 28, 2025 Understanding CVE-2025-55315: What CISOs, security engineers, and sysadmins should know
October 22, 2025 Toward greater transparency: Introducing machine-readable Vulnerability Exploitability Xchange (VEX) for Azure Linux and beyond
November 12, 2024 Toward greater transparency: Publishing machine-readable CSAF files
June 27, 2024 Toward greater transparency: Unveiling Cloud Service CVEs
April 9, 2024 Toward greater transparency: Security Update Guide now shares CWEs for CVEs
January 6, 2023 Publishing CBL-Mariner CVEs on the Security Update Guide CVRF API
January 11, 2022 Coming Soon: New Security Update Guide Notification System
February 9, 2021 Continuing to Listen: Good News about the Security Update Guide API
January 13, 2021 Security Update Guide Supports CVEs Assigned by Industry Partners
December 8, 2020 Security Update Guide: Let’s keep the conversation going
November 9, 2020 Vulnerability Descriptions in the New Version of the Security Update Guide
Relevant Resources
- The new Hotpatching feature is now generally available. Please see Hotpatching feature for Windows Server Azure Edition virtual machines (VMs) for more information.
- Windows 10 and Windows 11 updates are cumulative. The monthly security release includes all security fixes for vulnerabilities that affect Windows 10 and Windows 11, in addition to non-security updates. The updates are available via the Microsoft Update Catalog. For information on lifecycle and support dates for Windows 10 and Windows 11 operating systems, please see Windows Lifecycle Facts Sheet.
- Microsoft is improving Windows Release Notes. For more information, please see What's next for Windows release notes.
- A list of the latest servicing stack updates for each operating system can be found in ADV990001. This list will be updated whenever a new servicing stack update is released. It is important to install the latest servicing stack update.
- In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features.
- Customers running Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates. See 4522133 for more information.
You can see these in more detail from the Deployments tab by selecting Known Issues column in the Edit Columns panel.
For more information about Windows Known Issues, please see Windows message center (links to currently-supported versions of Windows are in the left pane).
KB Article Applies To
5082060 Windows Server 2022 23H2
5082063 Windows Server 2025
5082142 Windows Server 2022
Released: Apr 14, 2026
April 2026 Security Updates - Release Notes - Security Update Guide - Microsoft
My Computer
System One
-
- OS
- Windows 11




