Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
April Patch Tuesday: Critical Vulnerabilities Addressed

April Patch Tuesday: Critical Vulnerabilities Addressed

Posted on April 15, 2026 By CWS

In April’s Patch Tuesday, significant security flaws have been addressed across multiple vendors, including SAP, Adobe, Microsoft, and Fortinet. These updates are crucial for safeguarding systems against potential data breaches and unauthorized access.

SAP and Adobe Vulnerabilities

A major focus of this month’s updates is an SQL injection vulnerability in SAP’s Business Planning and Consolidation and Business Warehouse applications, identified as CVE-2026-27681 with a CVSS score of 9.9. This flaw allows low-privileged users to execute arbitrary SQL commands, posing risks of data extraction and manipulation. The vulnerability could lead to disrupted business operations and potential data theft, as explained by Onapsis and Pathlock.

Adobe has addressed a critical remote code execution vulnerability in Acrobat Reader, noted as CVE-2026-34621 with a CVSS score of 8.6, which is currently being exploited in the wild. Additionally, Adobe patched five critical flaws in ColdFusion that could lead to serious security breaches, including arbitrary code execution and denial-of-service attacks.

Fortinet and Microsoft Security Fixes

Fortinet’s updates include fixes for two critical vulnerabilities in FortiSandbox, both carrying a CVSS score of 9.1. These flaws could allow attackers to bypass authentication and execute unauthorized commands, emphasizing the need for immediate updates to FortiSandbox JRPC API and related systems.

Microsoft also released fixes for 169 security issues, including a critical spoofing vulnerability in SharePoint Server, CVE-2026-32201. This defect could expose sensitive information and facilitate data theft through ransom demands, as highlighted by Immersive’s Kev Breen.

Additional Vendor Updates

Beyond these major players, a wide array of other vendors have rolled out security updates. This includes companies like Apple, Cisco, Google, IBM, and many more, covering a wide range of products and services. These patches are essential for protecting systems from exploitation and ensuring data integrity.

The breadth of this month’s updates underscores the ongoing efforts of software providers to address security vulnerabilities. Users are strongly encouraged to apply these patches promptly to mitigate risks of cyber threats.

As the digital landscape continues to evolve, maintaining up-to-date security measures is crucial for preventing potential breaches and ensuring the safety of sensitive information.

The Hacker News Tags:Adobe security, authentication bypass, Cybersecurity, data breach, Fortinet updates, Microsoft patches, remote code execution, SAP vulnerabilities, security updates, SQL injection

Post navigation

Previous Post: Tech Giants Under Fire for Ignoring Privacy Opt-Outs
Next Post: Nginx Servers at Risk Due to Exploited Vulnerability

Related Posts

Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex The Hacker News
North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers The Hacker News
New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit The Hacker News
Kickstart Your Intelligent Workflow Program with 3 Key Strategies Kickstart Your Intelligent Workflow Program with 3 Key Strategies The Hacker News
Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices The Hacker News
Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights New Vulnerabilities, Sets Federal Deadlines
  • Gardyn Smart Garden Flaws Risk Remote Control by Hackers
  • British Hacker Admits to Stealing Millions in Cryptocurrency
  • Critical iTerm2 SSH Flaw Found: Text to Code Execution
  • Exploit Targets Windows Snipping Tool Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights New Vulnerabilities, Sets Federal Deadlines
  • Gardyn Smart Garden Flaws Risk Remote Control by Hackers
  • British Hacker Admits to Stealing Millions in Cryptocurrency
  • Critical iTerm2 SSH Flaw Found: Text to Code Execution
  • Exploit Targets Windows Snipping Tool Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark