Microsoft Patch Tuesday for April 2026 fixed actively exploited SharePoint zero-day
2026-04-15T08:51:45Z•f5c8b58ebaa03237b25fdbd6343d94a5df2f2aed44cad98fefa3901f235721bc
Basic-FitBooking.comCISACVE-2025-0520CVE-2026-32201Citizen LabDLL sideloadingKnown Exploited VulnerabilitiesMicrosoftOperation AtlanticPatch TuesdayPlugXRCERockstar GamesSharePointShinyHuntersShowDocSignalWebloccrypto theftdata breachiPhone forensicszero-day
What happened
Multiple security incidents and disclosures reported: Microsoft April 2026 Patch Tuesday fixed 165 vulnerabilities, including an actively exploited critical SharePoint zero-day (CVE-2026-32201). A critical RCE in ShowDoc (CVE-2025-0520, CVSS ~9.4) is being actively exploited. Significant breaches and leaks include Basic-Fit (≈1M members’ personal and banking data), an 8.1GB Rockstar Games data leak claimed by ShinyHunters, and Booking.com customer data access (contained). Malware and abuse incidents: a fake Claude AI installer distributing PlugX via DLL sideloading. Law-enforcement operation “
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f5c8b58ebaa03237b25fdbd6343d94a5df2f2aed44cad98fefa3901f235721bc
- Enrichment time
- 2026-04-15T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.