Don’t Wait for a Patch. Mitigate RedSun Zero-Day Risk in Microsoft Defender Today

2026-04-23T20:51:52Z4bb428d6473c75789d54857eec5f028c3727ce3f4c83c6b29c858adb92f6a2d7
LPEMicrosoft DefenderOpenClawOracle Critical Patch Update April 2026Patch Tuesday April 2026RedSunVMDRactively exploitedautonomous AI agentcloud securitydeep scanlocal privilege escalationpatch remediationremediation benchmarkingthird-party vulnerabilitiesvulnerability managementzero-day

What happened

This Qualys feed highlights several high-priority security items for April 2026. Most urgent: RedSun — a Microsoft Defender zero-day Local Privilege Escalation (LPE) that can allow a low‑privileged user to gain SYSTEM on Windows without a kernel exploit or administrator interaction; Qualys urges immediate mitigations rather than waiting for a Defender patch. Other notable items: Oracle’s April 2026 Critical Patch Update (481 vulnerabilities across multiple product families); Microsoft & Adobe Patch Tuesday (163 Microsoft vulnerabilities, including eight criticals, one publicly‑disclosed zero‑d

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
4bb428d6473c75789d54857eec5f028c3727ce3f4c83c6b29c858adb92f6a2d7
Enrichment time
2026-04-23T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.