Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

2026-04-17T19:24:19Z78a0a5cda90061a74fcf161d11bed46777eafe7d31961b55bfe98f9aaea52fb7
Apache ActiveMQCISA-KEVCiscoDDoS-takedownMicrosoft DefenderNISTObsidianPHP ComposerPatch TuesdayRATSAPShowDoc RCEactive-exploitationbotnetcritical-vulnerabilitiesmalicious-extensionsn8nnginx-uisupply-chain-phishingzero-day

What happened

A multi-topic security roundup from The Hacker News (Apr 14–17, 2026) reporting numerous actively exploited and high-severity flaws across widely used products. Key items: multiple Microsoft Defender zero-days (codenamed BlueHammer, RedSun, UnDefend) being exploited for privilege escalation with at least two unpatched; Apache ActiveMQ CVE-2026-34197 added to CISA KEV and observed in the wild; critical nginx-ui authentication-bypass (CVE-2026-33032) enabling full Nginx takeover; ShowDoc RCE (CVE-2025-0520) actively exploited; large Microsoft Patch Tuesday fixing 169 flaws including high-sev SAP

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
78a0a5cda90061a74fcf161d11bed46777eafe7d31961b55bfe98f9aaea52fb7
Enrichment time
2026-04-17T19:24:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.