Patch Tuesday, April 2026 Edition

2026-04-17T07:23:28Zea9f4981f5cc05a9551b1fdf6db140ab01d72c74fa96ec8b2669a8d9be716e44
APT token harvestingAdobe Reader RCEAisuruBlueHammerCanisterWormDDoSDaniil ShchukinGandCrabGoogle Chrome zero-dayIoT botnetsIran-targetingJackSkidKimwolfKimwolf botmaster Dort','phishing-as-a-service','Starkiller','MMicrosoft Office token theftMicrosoft Patch TuesdayMossadREvilRussian military intelligenceSharePoint zero-dayStryker incidentUNKN doxingWindows Defenderrouter vulnerabilitieswiper malware

What happened

A collection of April–March 2026 security incidents: Microsoft released fixes for 167 vulnerabilities (including a SharePoint Server zero-day and a publicly disclosed Windows Defender weakness called “BlueHammer”); Google Chrome received its fourth zero-day patch of 2026; and Adobe issued an emergency Reader update for an actively exploited RCE. Separately, actors linked to Russian military intelligence exploited known router flaws to harvest Microsoft Office authentication tokens from more than 18,000 networks without malware. Law enforcement disrupted four large IoT botnets (Aisuru, Kimwolf,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
ea9f4981f5cc05a9551b1fdf6db140ab01d72c74fa96ec8b2669a8d9be716e44
Enrichment time
2026-04-17T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Patch Tuesday, April 2026 Edition · Baitaphish