SharePoint Server is the emergency — it is being exploited in the wild. CVE-2026-32201 is a spoofing / improper-input-validation flaw (6.5) that Microsoft and every counter mark exploited at release. It is an internet-facing collaboration server, so the exposed asset and the active exploitation point the same way: patch it first, on an emergency change. Its low 6.5 score is exactly why a severity-ranked queue would miss it.
'BlueHammer' is a Defender elevation flaw that went from disclosed to KEV in eight days. CVE-2026-33825 (7.8) elevates to SYSTEM through a race in Defender's remediation engine. Public PoC circulated at release; CISA added it to KEV on 22 April, and by late June ransomware crews were using it. Confirm your Defender platform auto-updated to 4.18.26030.3011 or later — this one closes itself on most estates, but verify rather than assume.
The 9.8 is real, unauthenticated and wormable — but it is not yet exploited, so it ranks third, not first. CVE-2026-33824 in the Windows IKE service extensions lets an unauthenticated attacker run code by sending crafted packets to any host with IKEv2 enabled (UDP 500/4500). It carries the highest score of the month and the worst ceiling, yet no source reports exploitation — evidence outranks severity, so it is the third emergency change, not the first. For internet-exposed IKEv2 endpoints, treat it as a co-lead.
All three are Act / 72-hour changes; the ranking is triage order, not a licence to defer. SharePoint (exploited) and BlueHammer (KEV, exploited) are the evidence lane; IKE (9.8, unexploited) is the structural lane. The model puts evidence ahead of structure deliberately — you patch what is being used before what merely could be — but every one of the three ships inside the same emergency window.
Everything else is normal-cycle. The release totals 163–167 CVEs with 8 Critical; outside the three units above nothing is exploited or in KEV. Note the operational tax: the Server 2025, 2022 and 2019 updates shipped with install-failure and domain-controller restart-loop bugs that forced out-of-band re-releases — stage on a canary before the fleet.
Why now. CVE-2026-32201 was exploited in the wild as a zero-day at release — Microsoft flags it exploited, Rapid7 and SecurityAffairs mark it 'Exploitation Detected'. It is a spoofing / improper-input-validation flaw on an internet-facing collaboration server, so the asset is directly reachable and the attack is already happening. It scores only 6.5, which means a queue ordered by CVSS files it below dozens of higher-scored bugs nobody is being attacked through — the exploitation is the entire signal, and it forces the emergency change.
This unit cannot slip. Assessed to cut 0 of the identified chains — see the cut section, where this is labelled as a judgement rather than a finding.
| Product | Package | Carries |
|---|---|---|
| SharePoint Server Subscription Edition | not established | resolve via vendor advisory before deployment |
| SharePoint Server 2019 | not established | resolve via vendor advisory before deployment |
| SharePoint Server 2016 | not established | resolve via vendor advisory before deployment |
Also inside: Some counters describe the impact as XSS-like — view or change disclosed information — rather than full code execution; the exploitation status, not the impact ceiling, is what makes this rank 1. Treat any public-facing SharePoint farm as the priority; internal-only farms are still Act but a shorter blast radius.
Patching is not remediation. CVE-2026-32201 was exploited before you could patch, so deploying the SharePoint update is remediation of the vulnerability, not of any intrusion that already used it. Hunt public-facing farms for anomalous authentication, unexpected content or permission changes, and web-shell artefacts in the exposure window — a spoofing entry point is typically the first move of a longer chain, not the objective.
Then. Apply the SharePoint security update for your edition (Subscription Edition / 2019 / 2016) to every farm server and run the SharePoint Products Configuration Wizard or PSConfig so the build is committed across the farm — a half-patched farm is still exposed. Prioritise internet-reachable farms.
There is no soft call on the tier: active exploitation forces Act by evidence regardless of the 6.5 score. If your severity-ordered process would rank this low, the judgement to override is your own queue — it ships first because it is under attack, not because it is severe.
Why now. CVE-2026-33825 — 'BlueHammer' — elevates a local foothold to SYSTEM through a time-of-check/time-of-use race in Defender's threat-remediation engine. It was publicly disclosed with proof-of-concept code at release, CISA added it to KEV on 22 April (eight days after the patch), and by late June ransomware gangs were exploiting it. It is an EoP, not a remote entry point, but it is confirmed exploited and KEV-listed — evidence lane, emergency change. It ranks below SharePoint only because SharePoint is the internet-facing entry point and this is the escalation stage.
This unit cannot slip. Assessed to cut 0 of the identified chains — see the cut section, where this is labelled as a judgement rather than a finding.
| Product | Package | Carries |
|---|---|---|
| Microsoft Defender Antimalware Platform (auto-update channel) | not established | resolve via vendor advisory before deployment |
Patching is not remediation. Public PoC existed at release and exploitation began within days, so any host that stayed on an old Defender platform build through late April sat in a window where a foothold could become SYSTEM. Verify the platform version that was actually running during that window rather than the version running today; where it lagged, hunt for privilege-escalation and remediation-tampering artefacts.
Then. Confirm Defender's antimalware platform auto-updated to 4.18.26030.3011 or later (Get-MpComputerStatus → AMProductVersion / AMEngineVersion). On most estates Defender platform updates deploy automatically, but air-gapped, WSUS-pinned or MDM-managed endpoints can lag — those are the ones to check by hand.
The soft call is the rank, not the tier: as a KEV-listed exploited flaw it is unambiguously Act. It sits at rank 2 because it requires a pre-existing local foothold, where SharePoint is the remote entry point; if your Defender platform is confirmed current fleet-wide, this unit is already discharged and SharePoint plus IKE are where the work is.
Why now. CVE-2026-33824 lets an unauthenticated remote attacker execute code by sending crafted packets to any Windows host with IKEv2 enabled (UDP 500/4500), with wormable potential per SecurityAffairs and ZDI. It is the highest-scored flaw of the month (9.8) and the worst ceiling. It ranks third only because no source reports it exploited or publicly disclosed — the structural lane sits below the evidence lane by design. That ordering is a triage rule, not a downgrade: this is still an Act / 72-hour change, and for any internet-exposed IKEv2 endpoint it is a co-lead with SharePoint.
This unit cannot slip. Assessed to cut 0 of the identified chains — see the cut section, where this is labelled as a judgement rather than a finding.
| Product | Package | Carries |
|---|---|---|
| Windows 11 25H2 / 24H2 | KB5083769 | CVE-2026-33824 |
| Windows 11 23H2 | KB5082052 | CVE-2026-33824 |
| Windows 10 22H2 (ESU) | KB5082200 | CVE-2026-33824 |
| Windows Server 2025 | KB5082063 | CVE-2026-33824 |
| Windows Server 2022 | KB5082142 | CVE-2026-33824 |
| Windows Server 2019 | KB5082123 | CVE-2026-33824 |
| Windows Server 2016 | KB5082198 | CVE-2026-33824 |
Also inside: The same cumulative closes seven other Critical flaws this cycle; only IKE is confirmed at 9.8. Six further Critical RCEs (CVE-2026-33827, -32157, -32190, -33114, -33115, -33826) are Critical but their individual scores were not established in the source set — do not assume any is 9.8.
Then. Deploy the per-product package for your build and reboot. As mitigation ahead of the reboot, block UDP 500/4500 from untrusted networks at the perimeter and disable IKEv2 where it is not required. STAGE FIRST: Server 2025 (KB5082063) shipped with install failures (OOB KB5091157) and Server 2022/2019 with LSASS/domain-controller restart-loop issues (OOB KB5091575 / KB5091573) — canary these before the fleet.
The genuine judgement is rank 3 versus rank 1 for the 9.8. The model puts evidence ahead of structure, so a confirmed-exploited 6.5 outranks an unexploited 9.8 — that is deliberate, because you patch what is being used before what merely could be. If your IKEv2 endpoints are internet-facing, override the ordering and treat IKE as a co-lead; the tier is Act either way.
The unauthenticated 9.8 IKE RCE ranks third, behind a confirmed-exploited 6.5 and a KEV-listed 7.8, because the model puts the evidence lane ahead of the structural lane.
Basis. SharePoint and BlueHammer carry attested in-the-wild exploitation (Microsoft's exploited flag; CISA KEV on 2026-04-22); IKE carries no exploitation signal in any source. The decision model prioritises evidence over structural severity by construction, so unexploited severity ranks below confirmed exploitation even at a higher CVSS. The ordering is a triage sequence within one Act tier, not a claim that IKE is less dangerous.
What would lower this. A KEV addition or credible in-the-wild report for CVE-2026-33824 would move it to the evidence lane and likely to rank 1, given its unauthenticated wormable profile. For estates whose IKEv2 endpoints are internet-facing, the exposure alone justifies treating it as a co-lead now.
None.
| Source | Admiralty | Used for |
|---|---|---|
| https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities | A1 | KEV read 2026-07-17: CVE-2026-33825 present (added 2026-04-22, due 2026-05-06); CVE-2026-32201 and CVE-2026-33824 absent |
| https://www.tenable.com/blog/microsofts-april-2026-patch-tuesday-addresses-163 | B2 | Count (163), Critical (8); SharePoint CVE-2026-32201 exploited zero-day (6.5); IKE CVE-2026-33824 9.8 unauthenticated RCE; BlueHammer 7.8 |
| https://www.rapid7.com/blog/post/em-patch-tuesday-april-2026/ | B2 | Count (167); SharePoint 'Exploitation Detected'; BlueHammer 'Exploitation More Likely'; IKE unauthenticated remote packet vector |
| https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tue | B2 | Count (167), Critical (8, 7 RCE + 1 DoS); Defender platform 4.18.26030.3011; per-version Windows KBs |
| https://www.bleepingcomputer.com/news/security/cisa-windows-bluehammer-flaw-no | B2 | BlueHammer confirmed exploited by ransomware gangs; KEV listing and post-patch exploitation timeline |
| https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-april-2026/ | B2 | Count (164); enumeration of the 8 Critical CVEs (7 RCE + 1 DoS); IKE unauthenticated code execution |
| https://www.thezdi.com/blog/2026/4/14/the-april-2026-security-update-review | B2 | Count (163; 247 with third-party); IKE wormable potential; SharePoint spoofing/XSS-like impact framing |
| https://support.microsoft.com/en-us/topic/april-14-2026-kb5083769 | A2 | Windows 11 25H2/24H2 package KB5083769 and builds of record (26200.8246 / 26100.8246) |