All posts

April 2026 Windows Update — 167 Fixes and 2 Zero-Days, Install It Now

4 min read

Microsoft's April 2026 Patch Tuesday landed on April 14th, and it's a monster. 167 security vulnerabilities patched, 8 rated Critical, and 2 zero-days that attackers are already using in real-world attacks. If you haven't restarted your PC since last week, do it today.

Here's the short version of what was fixed, why it matters, and how to get it installed.

Windows Update screen showing updates being installed
Photo by Pexels
167
vulnerabilities patched this month8 Critical (7 remote code execution, 1 denial-of-service), plus 2 actively exploited zero-days. One of the biggest Patch Tuesdays Microsoft has shipped in over a year.

The Two Zero-Days (The Ones Being Exploited Right Now)

A zero-day is a flaw that attackers were using before Microsoft had a patch ready. Every day your PC sits without this update is another day those attacks work on it.

2 zero-days — actively exploited

CVE-2026-32201 — SharePoint spoofing — A flaw in Microsoft SharePoint Server that lets an attacker impersonate a trusted source, access confidential data, or modify files. Mostly a business concern, but anyone who uses SharePoint or OneDrive for Business should pay attention.
CVE-2026-33825 — Defender privilege escalation — A flaw in Microsoft Defender (the built-in antivirus on every Windows PC) that lets an attacker who's already on the system promote themselves to full SYSTEM-level access. Fixed in Defender Antimalware Platform version 4.18.26050.3011 — which most PCs will have picked up automatically by now, but it's worth checking.

The Other Scary Ones

Beyond the zero-days, these are the Critical flaws that stand out:

That last one is why "I don't click dodgy links" isn't enough anymore. You don't have to click. You just have to look.

How to Install It

  1. Open Settings (press Windows key + I)
  2. Click Windows Update (Windows 11) or Update & Security (Windows 10)
  3. Click Check for updates
  4. Let it download and install — typically 10–30 minutes depending on your PC and connection
  5. Restart when prompted — the fixes don't take effect until you do. Don't let the "restart pending" notification sit there all week
Pro tip: The cumulative update for Windows 11 this month is KB5083769 (for 24H2 and 25H2). If you want to check it's installed, go to Settings → Windows Update → Update history and look for that number.

Remote Desktop Got a Security Upgrade Too

On top of the vulnerability fixes, Microsoft added new protections against phishing attacks delivered via .rdp files. These are Remote Desktop shortcut files that scammers have been emailing people to trick them into connecting to an attacker-controlled machine. If you've ever received a random .rdp file in an email, you'll know why this matters. After this update, Windows is more cautious about what those files are allowed to do.

Still on Windows 10?

Windows 10 support officially ended in October 2025, but this month's update (KB5082200) is still being delivered to PCs enrolled in the free Extended Security Updates (ESU) programme. If you haven't signed up for ESU yet, you're not getting any of these fixes — and the gap between what's patched on your PC and what attackers know about widens every month.

The free ESU runs until October 2026. After that, Windows 10 is completely unprotected for home users unless you pay for it.

If Updates Are Failing

A PC that can't update is a PC that can't protect itself. If Windows Update is stuck, giving error codes, or looping endlessly — that's a repair job in itself. Common causes are low disk space, corrupted update files, or old antivirus software clashing with Defender. See my guide on common PC problems or how to speed up a slow Windows 11 PC if disk space is the issue.

For the full technical details, Bleeping Computer's breakdown covers every CVE, and Krebs on Security has analysis of the most important ones.

Mark — Your Local Computer Guy
Mark

Mark has been fixing computers since the late '90s and went self-employed in 2008. Based in St Helens since 2013, he works evenings and weekends from his home in Laffak — friendly, affordable repairs for PCs, laptops, and Macs. See reviews on Google

Updates failing or something not right?

If Windows Update is stuck, your PC is running worse since you installed, or you're not sure you're protected — get in touch and I'll sort it.