Patch Tuesday cycleApril 2026 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

April 2026 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 113 operational patch records link 239 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

113Patch recordsStable operational entries, not CVE duplicates
239Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
14Accelerated actionsOut-of-band action
1Revised entriesCanonical history remains visible

April 2026 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
113 matching recordsPage 1 of 6
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Experience Manager Screens to the fixed Adobe releaseAPSB26-34 · Updated 2026-04-14
Product and releaseAdobe Experience Manager ScreensFeature Pack 11.8
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

Adobe published APSB26-34 on Patch Tuesday for Adobe Experience Manager Screens. The bulletin links 4 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-34
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.4; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.4
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB26-38 · Updated 2026-04-14
Product and releaseAdobe ColdFusionUpdate 7, Update 19
Review linked CVEs (7) No confirmed exploitation stated

Operational summary

Adobe published APSB26-38 on Patch Tuesday for Adobe ColdFusion. The bulletin links 7 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-38
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.3; Adobe priority 1

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (7)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.3
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe DNG SDK to the fixed Adobe releaseAPSB26-41 · Updated 2026-04-14
Product and releaseAdobe DNG SDKDNG SDK 1.7.1 build 2536
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB26-41 on Patch Tuesday for Adobe DNG SDK. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-41
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.5; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.4
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Photoshop to the fixed Adobe releaseAPSB26-40 · Updated 2026-04-14
Product and releaseAdobe PhotoshopFixed release detail requires source review
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-40 on Patch Tuesday for Adobe Photoshop. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-40
Platform
See Adobe bulletin
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Acrobat Reader to the fixed Adobe releaseAPSB26-44 · Updated 2026-04-14
Product and releaseAdobe Acrobat ReaderFixed release detail requires source review
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-44 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-44
Platform
See Adobe bulletin
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.6

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe FrameMaker to the fixed Adobe releaseAPSB26-36 · Updated 2026-04-14
Product and releaseAdobe FrameMakerFrameMaker 2026, FrameMaker 2022 Update 9
Review linked CVEs (11) No confirmed exploitation stated

Operational summary

Adobe published APSB26-36 on Patch Tuesday for Adobe FrameMaker. The bulletin links 11 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-36
Platform
Windows
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (11)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB26-32 · Updated 2026-04-14
Product and releaseAdobe InDesignID21.3, ID20.5.3
Review linked CVEs (9) No confirmed exploitation stated

Operational summary

Adobe published APSB26-32 on Patch Tuesday for Adobe InDesign. The bulletin links 9 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-32
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (9)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB26-33 · Updated 2026-04-14
Product and releaseAdobe InCopy21.3, 20.5.3
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-33 on Patch Tuesday for Adobe InCopy. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-33
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Bridge to the fixed Adobe releaseAPSB26-39 · Updated 2026-04-14
Product and releaseAdobe Bridge15.1.5 (LTS), 16.0.3
Review linked CVEs (6) No confirmed exploitation stated

Operational summary

Adobe published APSB26-39 on Patch Tuesday for Adobe Bridge. The bulletin links 6 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-39
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (6)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB26-42 · Updated 2026-04-14
Product and releaseAdobe Illustrator29.8.6, 30.3
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-42 on Patch Tuesday for Adobe Illustrator. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-42
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Connect to the fixed Adobe releaseAPSB26-37 · Updated 2026-04-14
Product and releaseAdobe Connect12.11, 2025.9
Review linked CVEs (8) No confirmed exploitation stated

Operational summary

Adobe published APSB26-37 on Patch Tuesday for Adobe Connect. The bulletin links 8 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-37
Platform
Windows and macOS, Windows
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (8)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.6
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft Power Apps Desktop ClientMSRC-2026-04-azure-release-notes · Updated 2026-04-14
Product and releaseMicrosoft Power Apps Desktop Client3.26032.10.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Power Apps Desktop Client.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-04-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.0
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Monitor AgentMSRC-2026-04-azure-release-notes · Updated 2026-04-14
Product and releaseAzure Monitor Agent1.35.9, 1.41.0
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Monitor Agent.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-04-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft HPC Pack 2019MSRC-2026-04-azure-release-notes · Updated 2026-04-14
Product and releaseMicrosoft HPC Pack 20196.3.8355
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2019.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-04-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5082398KB5082398 · Updated 2026-04-14
Product and releaseMicrosoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 3.5 on Windows Server 2012 R2, plus 1 more2.0.50727.8982 & 3.0.30729.8976
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 3.5 on Windows Server 2012 R2, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5082398
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5082400KB5082400 · Updated 2026-04-14
Product and releaseMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)4.8.4801.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5082400
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5082402KB5082402 · Updated 2026-04-14
Product and releaseMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)4.7.4141.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5082402
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5082403KB5082403 · Updated 2026-04-14
Product and releaseMicrosoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012 R2, plus 1 more4.8.4801.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012 R2, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5082403
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5082404KB5082404 · Updated 2026-04-14
Product and releaseMicrosoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)4.8.4801.0
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5082404
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5082406KB5082406 · Updated 2026-04-14
Product and releaseMicrosoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation)2.0.50727.8982 & 3.0.30729.8976
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5082406
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0