Patch Tuesday, April 2026 Edition
2026-04-17T07:23:28Z•ea9f4981f5cc05a9551b1fdf6db140ab01d72c74fa96ec8b2669a8d9be716e44
APT token harvestingAdobe Reader RCEAisuruBlueHammerCanisterWormDDoSDaniil ShchukinGandCrabGoogle Chrome zero-dayIoT botnetsIran-targetingJackSkidKimwolfKimwolf botmaster Dort','phishing-as-a-service','Starkiller','MMicrosoft Office token theftMicrosoft Patch TuesdayMossadREvilRussian military intelligenceSharePoint zero-dayStryker incidentUNKN doxingWindows Defenderrouter vulnerabilitieswiper malware
What happened
A collection of April–March 2026 security incidents: Microsoft released fixes for 167 vulnerabilities (including a SharePoint Server zero-day and a publicly disclosed Windows Defender weakness called “BlueHammer”); Google Chrome received its fourth zero-day patch of 2026; and Adobe issued an emergency Reader update for an actively exploited RCE. Separately, actors linked to Russian military intelligence exploited known router flaws to harvest Microsoft Office authentication tokens from more than 18,000 networks without malware. Law enforcement disrupted four large IoT botnets (Aisuru, Kimwolf,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- ea9f4981f5cc05a9551b1fdf6db140ab01d72c74fa96ec8b2669a8d9be716e44
- Enrichment time
- 2026-04-17T07:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.