Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
April Patch Tuesday: Critical Vulnerabilities Addressed

April Patch Tuesday: Critical Vulnerabilities Addressed

Posted on April 15, 2026 By CWS

In April’s Patch Tuesday, significant security flaws have been addressed across multiple vendors, including SAP, Adobe, Microsoft, and Fortinet. These updates are crucial for safeguarding systems against potential data breaches and unauthorized access.

SAP and Adobe Vulnerabilities

A major focus of this month’s updates is an SQL injection vulnerability in SAP’s Business Planning and Consolidation and Business Warehouse applications, identified as CVE-2026-27681 with a CVSS score of 9.9. This flaw allows low-privileged users to execute arbitrary SQL commands, posing risks of data extraction and manipulation. The vulnerability could lead to disrupted business operations and potential data theft, as explained by Onapsis and Pathlock.

Adobe has addressed a critical remote code execution vulnerability in Acrobat Reader, noted as CVE-2026-34621 with a CVSS score of 8.6, which is currently being exploited in the wild. Additionally, Adobe patched five critical flaws in ColdFusion that could lead to serious security breaches, including arbitrary code execution and denial-of-service attacks.

Fortinet and Microsoft Security Fixes

Fortinet’s updates include fixes for two critical vulnerabilities in FortiSandbox, both carrying a CVSS score of 9.1. These flaws could allow attackers to bypass authentication and execute unauthorized commands, emphasizing the need for immediate updates to FortiSandbox JRPC API and related systems.

Microsoft also released fixes for 169 security issues, including a critical spoofing vulnerability in SharePoint Server, CVE-2026-32201. This defect could expose sensitive information and facilitate data theft through ransom demands, as highlighted by Immersive’s Kev Breen.

Additional Vendor Updates

Beyond these major players, a wide array of other vendors have rolled out security updates. This includes companies like Apple, Cisco, Google, IBM, and many more, covering a wide range of products and services. These patches are essential for protecting systems from exploitation and ensuring data integrity.

The breadth of this month’s updates underscores the ongoing efforts of software providers to address security vulnerabilities. Users are strongly encouraged to apply these patches promptly to mitigate risks of cyber threats.

As the digital landscape continues to evolve, maintaining up-to-date security measures is crucial for preventing potential breaches and ensuring the safety of sensitive information.

The Hacker News Tags:Adobe security, authentication bypass, Cybersecurity, data breach, Fortinet updates, Microsoft patches, remote code execution, SAP vulnerabilities, security updates, SQL injection

Post navigation

Previous Post: Tech Giants Under Fire for Ignoring Privacy Opt-Outs
Next Post: Nginx Servers at Risk Due to Exploited Vulnerability

Related Posts

64% of 3rd-Party Applications Access Sensitive Data Without Justification 64% of 3rd-Party Applications Access Sensitive Data Without Justification The Hacker News
GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms The Hacker News
How Attackers Exploit SOC Workloads Beyond Phishing Emails How Attackers Exploit SOC Workloads Beyond Phishing Emails The Hacker News
Google Integrates Rust DNS Parser in Pixel 10 for Security Google Integrates Rust DNS Parser in Pixel 10 for Security The Hacker News
APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More The Hacker News
LeakNet Ransomware Adopts ClickFix for Attacks LeakNet Ransomware Adopts ClickFix for Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Gafgyt Variant C0XMO Targets Linux Systems
  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Gafgyt Variant C0XMO Targets Linux Systems
  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark