Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
April Patch Tuesday: Critical Vulnerabilities Addressed

April Patch Tuesday: Critical Vulnerabilities Addressed

Posted on April 15, 2026 By CWS

In April’s Patch Tuesday, significant security flaws have been addressed across multiple vendors, including SAP, Adobe, Microsoft, and Fortinet. These updates are crucial for safeguarding systems against potential data breaches and unauthorized access.

SAP and Adobe Vulnerabilities

A major focus of this month’s updates is an SQL injection vulnerability in SAP’s Business Planning and Consolidation and Business Warehouse applications, identified as CVE-2026-27681 with a CVSS score of 9.9. This flaw allows low-privileged users to execute arbitrary SQL commands, posing risks of data extraction and manipulation. The vulnerability could lead to disrupted business operations and potential data theft, as explained by Onapsis and Pathlock.

Adobe has addressed a critical remote code execution vulnerability in Acrobat Reader, noted as CVE-2026-34621 with a CVSS score of 8.6, which is currently being exploited in the wild. Additionally, Adobe patched five critical flaws in ColdFusion that could lead to serious security breaches, including arbitrary code execution and denial-of-service attacks.

Fortinet and Microsoft Security Fixes

Fortinet’s updates include fixes for two critical vulnerabilities in FortiSandbox, both carrying a CVSS score of 9.1. These flaws could allow attackers to bypass authentication and execute unauthorized commands, emphasizing the need for immediate updates to FortiSandbox JRPC API and related systems.

Microsoft also released fixes for 169 security issues, including a critical spoofing vulnerability in SharePoint Server, CVE-2026-32201. This defect could expose sensitive information and facilitate data theft through ransom demands, as highlighted by Immersive’s Kev Breen.

Additional Vendor Updates

Beyond these major players, a wide array of other vendors have rolled out security updates. This includes companies like Apple, Cisco, Google, IBM, and many more, covering a wide range of products and services. These patches are essential for protecting systems from exploitation and ensuring data integrity.

The breadth of this month’s updates underscores the ongoing efforts of software providers to address security vulnerabilities. Users are strongly encouraged to apply these patches promptly to mitigate risks of cyber threats.

As the digital landscape continues to evolve, maintaining up-to-date security measures is crucial for preventing potential breaches and ensuring the safety of sensitive information.

The Hacker News Tags:Adobe security, authentication bypass, Cybersecurity, data breach, Fortinet updates, Microsoft patches, remote code execution, SAP vulnerabilities, security updates, SQL injection

Post navigation

Previous Post: Tech Giants Under Fire for Ignoring Privacy Opt-Outs
Next Post: Nginx Servers at Risk Due to Exploited Vulnerability

Related Posts

UAT-10362: LucidRook Malware Targets Taiwanese NGOs UAT-10362: LucidRook Malware Targets Taiwanese NGOs The Hacker News
Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks The Hacker News
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks The Hacker News
Mustang Panda Exploits Cloud Service in Indian Cyber Attacks Mustang Panda Exploits Cloud Service in Indian Cyber Attacks The Hacker News
Unveiling Eight Attack Vectors in AWS Bedrock Unveiling Eight Attack Vectors in AWS Bedrock The Hacker News
Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing Campaigns The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark