Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Ivanti: April 2026 Patch Tuesday: Record Microsoft Updates & AI Threats

Ivanti
07/30/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


We're going to go ahead and get started. Todd, we had the second largest Patch Tuesday from Microsoft in history now. One-upped only by six CVEs from October last year. This was a big one. That was crazy, I'll tell you. Not only that, our slide deck today is the biggest slide deck we've ever had. There was a lot of stuff released yesterday and there was a lot of stuff between the Patch Tuesdays that came out. We had a lot of material to get through today, Chris. Absolutely. We're going to go ahead and get started. Now, one thing I know a couple of people might be thinking is, hey, it seemed like it was a long time to wait for the content to come out yesterday. We do apologize for that, but Microsoft actually broke our content tooling with some of the changes that went out. We had to actually fix an issue and then get back in and do all the content release because we had to make a change in there. Little bit of excitement for the team. They had a long night. Long and Richard are on supporting a lot of our technical questions today. Be gentle if they're a little bit slow to respond. They're on a couple hours of sleep right now. But we have a couple of zero days we're going to talk about leading up to Patch Tuesday. Then we're going to talk about the Patch Tuesday release, and we'll talk about a few other changes that are going on that people are probably going to want to be aware of. But the core of the updates from yesterday, we've got seven bulletins or updates that we'll be talking about from the Microsoft side, and then seven from the Adobe side. Now, Adobe did have 11 total. There's a few of those that aren't automated in the Creative Suite that we support. Those are ones that yes, they released for those as well. A lot of those are a lot more of the middleware or development tools that we don't support with our automated patch management solution. That's why we were talking about only seven of the 11 there, just for anybody who's newer to the event. As we wrap up, Todd's going to walk us through all of the updates individually and talk about some of the details of those, if there's any known issues and things, and then we'll wrap on what we call between the Patch Tuesdays. This goes in and talks a lot more about those updates that happened between last month and this month that you'll want to potentially be aware of. Without further ado, let's get into some of the news. For this, my apologies, little housekeeping. If you look next to the chat there, there is a Docs section. In there, the first thing on that list is the April Patch Tuesday presentation. If you crack that open, you're going to find all of the links on this in the new slide. That's what I'm about to go through. But I'm actually going to go over to my screen share so we can walk through a couple of those articles more specifically. Follow along in the presentation if you want to grab that. I'm going to be sharing my screen so that we can walk through a couple of these articles. First on the list, Adobe Reader. Besides the update that came out yesterday that resolved two additional CVEs, I believe it was, there was a zero day that hit just last Friday. This came out the middle of the day as far as advisory, but the update actually didn't drop until much later in the evening. The team was able to pull that in and we did get that into our catalog very quickly into the following morning. Again, apologies for that, but we're at the mercy of those updates becoming available for us to actually download and test. But we did make sure to get that out within. We have targets for the different types of content that we support. Our content team, we've got split between the US and India. They are constantly on the lookout for different things like a zero day, where we want to prioritize that, bump it to the front of the queue and get it out the door as quickly as possible, so you-all can resolve that as quickly as possible. This one did actually fall into the weekend and the team was able to get it out within our target which typically for a zero day update is within 24 hours of less from releasing the vendor. Usually, we're closer to eight hours or so or less for most of those zero days. Great work by the team in getting that done. But that zero day is plugging a vulnerability that's been targeted since December last year. In this case, even just opening the PDF is enough to trigger the exploit from the reports that we've been seeing. This is just giving you a little bit of detail on the vulnerability. There's a couple of samples that were captured early on that this PDF was going by certain names. Invoice 540, that PDF was one of the first ones that appeared in VirusTotal, which led the researchers to very rightly understand that there was a social engineering element to this. They're trying to throw something at a user that's easily confusing and makes somebody want to open said document to see if it is something that actually needed to be aware of. In that case, automatically is able to trigger the exploit in this case. Remote code execution with sandbox escape. It's a particularly nasty one. That's definitely making it so that your Adobe Reader updates across your end-user environment are definitely a high priority this month. The two CVEs that released yesterday, less of a concern. Nothing exploited there. It's the Friday update that we're really concerned about. But because they're cumulative, you can just do yesterday's update and you will be covered for both. The second one dates back a little bit earlier in the month. Google Chrome had their fourth zero-day for this month. The latest one, CVE-2026-5281, they haven't released too much for details about the actual exploit itself, the attack, and what tactics were being used there. But Google had released that on the first, and that was the fourth zero-day that they've had this year. This is one of those areas where, especially for those of you who are newer to this series, we talk a lot about how you're thinking through your approach to vulnerability remediation. We've talked a lot about exposure management and that shift in mindset. You're not going through a linear process anymore of identifying what's vulnerable, prioritizing approvals, then remediation, and so on. It really needs to be more of a continuous process and things working in parallel, where you define the outcome you want to achieve and configure for that, and the teams can work in parallel and reconcile what their findings are to make sure that overall you're meeting your compliance goals. For those of you who are using the Ivanti Neurons product, even in the experience that you'll get out of the box, we're really designed for trying to help people to easily slot into that multi-stream approach. Regular maintenance, what you'd be starting as of yesterday and doing the bulk of your updates that aren't urgent, just the regular normal maintenance that you're doing for the month. Then we've got a priority updates track. This is where browser updates, again, with this as an example, they've had four zero-days this year, two of them very closely back-to-back in March. You would want to put something like browser updates into your priority updates bucket and even have that happening on a weekly or even daily basis to check more frequently for certain applications that are continuous release, and when they do have a zero-day, maybe something that splits by very quickly if you're not constantly vigilantly watching for it. Organizations that are doing more of their regular maintenance in that once a month track starting around Patch Tuesday, having certain applications like your browsers and your apps like Zoom or things like that that are highly easily user-targeted, happening more on a weekly basis, that priority updates track, they find that their risk window shrinks significantly. Then you'll also have things like the zero-day bucket. If you did see the Adobe Reader update come out last weekend and you wanted to respond to it very quickly, maybe you were already seeing examples of that PDF showing up targeting your users, you could drop that into the zero-day response, and that could be another task that you set to run on a daily basis. That's the mind shift over to that more exposure management type experience. The big thing that's now compounding this, and we're going to talk about this at a few different points today to look at what to expect, the different knock-on effects of what's going on. Many of you have probably heard about Project Mythos. This is Anthropic's new model. Think of the different models that they've released. This one is their largest yet. It's a very sophisticated, very powerful model. It's also very expensive. But basically, it's able to go in and identify exposures within a code base much more easily, much more quickly, and even see what's exploitable. The different challenges that we're going to expect to see from this are going to be potentially more exposures being found in the wild versus internally within organizations in the early part of this. Longer term, when organizations start to adopt these types of AI tools, we should see the number of findings resolved prior to code getting out to market. Those ideally would go up and less of them would actually get out to the wild. But in the first 18 months here, we're probably going to have a massive spike in the number of findings out in the wild. That's going to be the real challenge. We can expect to see more frequent updates and more urgent updates from a lot of different software titles. But as the big players start to adopt that, hopefully that means that they're finding more of the exposures before they even reach market. If they introduce a new exposure in their code, they're going to be using tools like Mythos to look for that and try to resolve those before they actually release. That's the ideal world. Now, there's other areas, and we're going to talk about Linux here in a little bit, and I'll mention another example there where that's going to be more difficult. Aside from the 2.0 days, there's this whole project Glasswing. That's the Mythos project and a number of vendors have been invited in to participate in this, and they're playing around with this new technology, and half the world is enthralled and excited, and the other half of the world is scared and shaking in their boots. There's going to be a lot of hype going out around this. The biggest things to keep in mind are, this is going to fundamentally change how vendors need to approach security within their code base. Not just third-party libraries, but this is a first-party code. In a project like any of the Ivanti products, we're already investigating use of AI tools to flush out security flaws and resolve them before code changes go out to the market. If a security researcher uses a tool like this to scan any of our products, and they find something, that's something that, again, just means there may be more volume of findings coming in for vendors like us. This won't be Ivanti only, it'll be all vendors in the market, especially the larger and more notable are going to get a lot more attention. Now, it is expensive to run a scan as powerful as this. If any of you have read about this, you may have seen estimates around that. But to find the OpenBSD vulnerability that was over 20 years old, that one cost about $20,000 to find that using AI. There's a high cost to the level of sophistication with this as well to begin with, and we'll see how that plays out. But it's not something that is just going to be in the hands of any threat researcher or threat actor. Nation-state funded threat actors will have the budget to be able to try to go use tools like this. Major vendors will have the budget to be able to use tools like this. Open source and smaller vendors are not going to be able to use something as powerful as Mythos because it will be too cost prohibitive. They'll still have to rely on slightly less sophisticated ways of doing that. But it is possible to do that. We've already experimented with a number of different AI tools for identifying code weaknesses and resolving them, and definitely doesn't take nearly as much cost as doing this. But this is more of a fully automated approach to it. Some interesting things happening there. If you read my blog post yesterday, the two major takeaways. One, expect that in the not too distant future here, that we're going to see a spike in the number of findings. Two, that's going to create a knock-on effect. One, that we need to try to be prepared for here, which is more findings on software titles throughout the environments that we're supporting, meaning more updates that need to be installed, and potentially a much faster continuous pace of that. If you're not already trying to adopt those additional parallel workstreams, the priority updates, the zero-day response, that type of mentality is how we're going to deal with the volume that's expected here. If you haven't already made that shift in certain areas, chances are you're going to need to start looking at that sooner rather than later to keep up with. Think of Chrome releasing one security update a week right now. What if that becomes twice a week, three times a week? What if it becomes daily? What if the Microsoft OS updates start coming out twice a month, and have security vulnerabilities in them, and some of them being zero-days? This is the pace that we need to anticipate and start to think about how we're going to get ahead on that. This article for Glasswing talks about a variety of different additional first-order effects that are going to be happening. Open-source, definitely going to be a larger concern because in some of those cases, you have a handful of people curating that project and then contributors periodically. Discovery of findings is going to be much different. There's going to be a larger range between findings and the cost of locating those findings. There's a remediation. These are the two that I'm probably wanting to call out the most for this audience. Remediation is going to be more critical. Now, this Forrester analyst is talking about it in terms of MDR, but in this case, remediation, the end result of remediation is, how do you actually resolve the finding? A lot of these are going to be in software, and that means either patch management or somebody applying some type of code change manually to that environment. CVE, we talk about this a lot. It's going to continue to degrade in its quality and ability to help us really prioritize effectively. If you're not already using a more robust scoring mechanism, like our vulnerability risk rating within the neurons platform and our RBVM platform, that's something you want to start to look at there as well because CVE is going to get overwhelmed by this. If you don't have a better refinement of what you need to resolve versus the things that you don't need to be as worried about, you're going to get overwhelmed with the sheer massive findings. Microsoft had 1,300 CVEs last year, and with this month, they're definitely on pace to overtake that again this year and have an increase there, and we're going to see that type of increase across the industry. That's just a little bit about some of the recent news and what to expect there. For those of you running a lot of Apple devices, this was notable. Apple actually updated the DarkSword exposure. It was a pretty nasty, wormable ability to go into exposed contacts and start to message out to additional contacts and spread at a very rapid pace. They supported that fix for the latest platforms, but they actually backported that back to iOS 18 recently here. That was noting how concerned they are about this particular exposure. Those of you who might have some older devices running, that may pertain to you. Most of us, if we're running those for corporate devices, we're probably sticking to the latest supported OSes. This might be more of just a consumer-based, but if you do have some older devices like a kiosk or something like that, this may be something you want to look into to make sure that all of your legacy devices are up-to-date. Remote desktop. Todd, this one is some new security warnings that were introduced when opening RDP files, correct? That's correct. They came out just with the updates yesterday here in April. People were wondering why they were getting all these new warnings when they were trying to use remote desktop. This article I pulled up talks through it, gives some examples of what's happening and how they've increased the security on remote desktop access. Yeah. A couple of key parts. The one, how to stay safe. RDP is an easy way in. If you're an organization that has RDP as a remote-facing entry point, not just an internal tool, that's definitely an attack factor for threat actors. This is trying to help to establish better security around that. That first launch dialogue, this is another one of those newer experiences that are being introduced here that surprised a few people with that, but some good information in here about what that new experience looks like, and some ways to make sure that you're verifying things correctly in there. That was a new change that definitely was noteworthy. Definitely saw a number of people discussing that on patchmanagement.org already as well. Microsoft also made some changes to the update channels for 365 apps. Todd, basically we're down to semiannual now, right? Yeah. Well, this is a heads up that they're going to change the semiannual enterprise channel to get monthly updates, which is defeating what this was originally put in place for. People did not want Office or 365 app updates so often, so they could choose this channel. All of a sudden, Microsoft announced they're going to change it to monthly updates. I'm wondering if this is going to be a precursor to an end of life on the way they're handling their channels. Microsoft has been changing these up over the last couple of years. By the way, this isn't going into effect. I think it takes place in June or July, so it's just a heads up. There it is, July. It's at the beginning of July. We don't have to worry about this just yet, but just a heads up if you're using that and you suddenly start seeing monthly updates on a channel you were expecting quarterly updates, this is where it's coming from. Yeah. Semiannual and monthly, arguably there's going to be very little difference between them after that July change, right? Yeah. You'll have current and then pick either of these, but really they're both behaving the same way now as of July. One thing that we talked about last month that we wanted to just make sure to circle back on and touch on real quick was the Windows Server 2016 ESU support. We surveyed the audience last month, and there was a very strong bit of feedback that there's a lot of people who are definitely going to need 2016 after the end of life. As many of you know, we do support ESU for, I mean, we've supported it since NT4, back very close to when I started with Shablik Technologies way back in the day. We were doing ESU for NT4, and we've supported ESU in almost every OS extended support program Microsoft has done over the years. There were a few that were nobody was really interested. Vista, I think, was one that we just didn't do because nobody raised their hand and say, yeah, we've got a ton of Vista, we need to support. No, nobody really did. But yeah, 2016 definitely had an overwhelming thumbs up from people saying, at least for a period of time in the first year or the first full year, or maybe even multi-year, a lot of you are anticipating having a footprint. We will definitely have 2016 support. Just wanted to confirm that just to make sure everybody's aware. Microsoft is also removing support for the Recovery Assistant from Windows. This is a command line utility that some of you may have had to use in the past. There, let's see. Apologies, I didn't read as much up on this. This one's been around forever, Chris. This goes way back to the XP days actually. Yeah. Not very secure though. A great tool, by the way, a lot of us used it, but they're finally end-of-lifing it due to security concerns, and they're going to the Get Help tool, which you can download and use. I was looking for the, okay, here it is, down here. I was looking for the, when will this transition? The desktop publishing app would be removed from Microsoft 365 after October 2026. That's the time frame we've got before there, before we switch from the legacy version to the Get Help command line or scripting options that are going to be available going forward. I think this was just, yeah, we provided this link in there as well. If you need to get a link to that command line utility, that's provided in that slide as a link, so you can go check that out. That wraps up the recent news and some of the big changes coming. Let's talk about the zero-day and the public disclosure real quick, and then we'll transition into the updates. First one here, this was the publicly disclosed issue in Microsoft Defender. It was an elevation of privilege vulnerability. The good news here is those of you relying on Defender, it should have already updated itself. Microsoft does encourage the use of some type of monitoring to make sure that your Defender systems are updating, a lot of times the first things that a threat actor will do is to disable many of those mechanisms. It's always good to have some type of additional checks and balances in place to make sure systems are staying updated, or in the case that a system does just break, something goes wrong and the updates no longer apply to it for some reason. But this was one that should have already been taken care of for you, but it was a public disclosure and did include proof of concept code. If the attacker does execute this well, they are able to get to system-level privileges on the local system if they take advantage of this. Definitely a powerful privilege escalation if they can get their hands on it. The second one is the one that- Chris, before you move on. Go ahead. Yeah. One note I pulled out of this and put on the slide is the fact that if you're not using Defender and you disabled it on your system, if you get scanned by a vulnerability scanner, it's going to show up as vulnerable because you don't have the latest version that's been updated. Microsoft said you're not at any danger, but just be aware that you're going to show up in an audit that you're not up-to-date with your Windows Defender files, which is not unusual. I mean, it's true for almost every application that you're not updating. Just be aware of that one. Here's the note that Todd was talking about in there. They did call that out here. It might be an exception that you'll have to do within your vulnerability scanner to make sure that that's explained. Microsoft SharePoint did have a server spoofing vulnerability. This one has been used in targeted attacks in the wild. The attacker who exploits this could view some sensitive information and even make changes to that disclosed information that they're able to get access to. You have confidentiality and integrity loss from this exposure. They can't remove access to it though. You still have availability, yay. Just a matter of if they see it and modify it, that may not help you much. Of course, IT is on the ball and I've got my updates applied and no, I don't want to reboot right now. Sorry, our team is already patching. Yeah. Todd and I are in the early adopters group within our organization. We had requested that all of our patch team be part of the early adopters group. They're already getting started on us for the week. This one is updated for SharePoint Server Subscription Edition, Server 2019 and Server 2016. Let's go down and see they made a change. Oh, they made the change later the same day. There was an informational, oh, they added an acknowledgement. I just saw the tag at the top saying there was a change. Since it was originally updated, I wanted to make sure I didn't miss something on that. That must have been tweaked later in the day yesterday. That wraps up the news. I'm going to jump back over to slides here real quick. We're going to talk about a couple of other things because I did say we're going to talk a little bit about Linux. Now, we're jumping back in on slide 9 of the presentation. For those of you who were following along on the side there, we just jumped through the slides 5-8, which had all the news links that I just went through. We have three Linux kernel vulnerabilities this month. One of the things that we talked about last year, the Linux kernel has its own CNA now. With that, there's a lot more visibility and diligence around disclosing kernel exposures as they get resolved. That's why we're seeing a lot more of those. Compared to last year, a lot more of the exposures that we're seeing from the Linux side are kernel focused. That's because they're getting a lot more visibility with that. Now, one of the things that I had mentioned about Mythos is the open-source community is definitely going to be one of the areas that's going to be hardest hit by the early use of AI tools like Mythos. If they're able to scan open-source codebases, new findings could be coming up pretty regularly. But if there's nobody behind that to go work on it, that could be challenging. That goes not just for the open-source Linux platforms, but any open-source technologies in general are going to be one of the areas that there's a lot more concern around. Now, for those that are supported by a large enterprise like Oracle, RHEL and Oracle Linux being an example, those ones will probably have a lot more faster response on getting security issues resolved that are found by third parties. But a less well-managed open-source library of some kind may be a different challenge. I know that we've had curl as an example, open-source libraries like that that are consumed in a variety of platforms. A finding gets discovered there and slowly gets resolved and consumed across a number of areas. If we have even more findings and if there's even more risky ones, that's one of those areas where there might be a lot more pain to come here from the shift that we're going to see in the market. That's definitely one of the things that the Forrester article called out was the open-source community. One of the reasons Anthropic gave $4 million to the open-source community for trying to help respond to and resolve things there, there definitely is an anticipation of additional pain there. That's just a side note again about how things are going to radically shift here in the next little while. But this one, it's a 9.8 CVSS score, race condition between two concurrent operations, the socket close path on one CPU and the right space notification handler on another is where this exposure comes into play. During that cleanup, when the TLS socket is being closed, the function call could allow the cancel pending. Let's see, the timing window exists where the work can be rescheduled after the cancellation attempt. Seems to be that race condition from the cancellation and cleanup versus somebody trying to reopen a call and do whatever they want with it. The second CVE also in the Linux kernel is a buffer overflow that could allow for the Wi-Fi subsystem to cause an out-of-bounds memory write. Insufficient bounds checking. I'm trying to see where some of these are not as clear on exactly what is going on there. Yeah, this particular one results in a drop an executable on your system basically. Okay, got it. Then the third vulnerability this month is in Linux Kernel Xen PrivCMD. It could allow arbitrary hypercalls to be issued from user space processors. While access is typically limited to root, this is allowing them to sneak in there and make additional requests from the user side. Xen security does have an additional advisory. You could see that XSA-482 there if you want details on this one. But in all three cases here, Linux kernel updating to the latest version will resolve those. That is the urgency this month on the Linux side is the kernel update as typical. That's where most of the Linux side nasty exposures come into play. On the Ivanti side this month, we had one security advisory in our Ivanti Neurons for ITSM platform. Those of you using the Cloud product, you don't have to worry, this is already taken care of. For those of you running the on-prem ITSM, there is an update and it resolves to OpenCVEs. I think lifecycle awareness, we don't have any news on that this month. Other than the mention we had around ESU and then Server 2016, we are less than a year out. January 2027 is that ESU date. Feels like a long way out, but as we all went through with the previous ESUs, they always sneak up on us very, very quickly. If you haven't already, start having those discussions now, planning, budgeting, that sort of thing for that ESU coverage. Now, unlike Windows 10, Microsoft has a little bit more cost for the server-side ESUs. Todd, they've typically done that based on number of CPUs in the past, right? Correct. That's on the server-side the way they price it. We'll see if they do the same thing. That's the way Server 2012 ESU was done. Anticipate the same for Server 2016. Yeah. Okay. I know we're stretching on time here, so I'm going to jump ahead over to the bulletins and releases, so Todd can run us through those. Okay, Chris. Thanks. Hello, everybody. Let's walk through, first of all, the Adobe releases that Chris mentioned. These are all rated critical because of the nature of the vulnerabilities within them. Chris talked about the zero-day in Acrobat and Reader. This one came out yesterday. It was not a zero-day, but obviously didn't include the fix for the previous update. Two vulnerabilities, one was rated critical and one important. One was a code execution vulnerability, one was an information disclosure vulnerability. Again, make sure you run through and update Acrobat and Reader, just to make sure you catch that zero-day that was released on Saturday morning. An update for Adobe Illustrator, only one vulnerability addressed this month, but also rated critical. Again, arbitrary code execution, so important to make sure that you get that updated in your Adobe Creative Cloud. Photoshop, one vulnerability addressed there, that was critical, latest version as well. Adobe Bridge, a few more vulnerabilities here. Six addressed, five of them are rated critical and one important. By the way, I do include a link to the Adobe site for all these, so if you want to go in and read more details about these, you can. Each one of these vulnerabilities are generally covered in a little more detail. I generally provide a list here, so at least you can see what they are and the appropriate versions. Versions of Bridge here, 15.1.4, which is their long-term service version and 16.0.2. Adobe Connect, this is a product we added to our catalog not too long ago. This is standalone application as well as a hosted portion. Adobe Connect 12.10 and the desktop application version is 2025.3. Nine vulnerabilities addressed yesterday, of which seven were critical and two important, so I'll have the list of them there. We also saw an update for InCopy. Two vulnerabilities here, both of those arbitrary code execution, and finally, Adobe InDesign got an update as well. A lot of things on the Creative Cloud side as well as standalone applications. As Chris mentioned, we cover the ones here that are in our catalog that we can patch with our product set. There were some additional applications as well that you should take a look at going to the Adobe security site to make sure that you have those covered. Jumping into Windows 11, top of the list here, obviously. Updates across the board. You'll note that a couple of months ago, they did break out Server 2025 under a separate set of KBs. It had been lumped in previously with the desktop versions, but now it's separate, which is nice. The binaries are separate as well, so we can manage those a little bit better. Massive, 128 vulnerabilities altogether across all of these different versions of Windows 11, including updates for the latest 26H1. That's, I don't want to call it a preview. It is a GA release, but it only runs on very specific hardware, so most of us aren't yet engaged with 26H1, but be aware that it's out there. Known issues, something new that showed up this month, the BitLocker issue. You might have seen that if you were reading through the release notes on the various operating systems. I like the way they call this an unrecommended BitLocker group policy configuration. There are some edge cases, and even Microsoft said it's an edge case where this will pop up. But in some cases, when you do the update, you may have to enter your BitLocker recovery key on first restart, which can really be a pain, especially if you don't have it handy and you have to go to your support people to get it. Just be aware that it does occur on Server 2025, Windows 11, 23H2, as well as the Windows 11, 24H2, and 25H2 version, so it's across the board here. This WSUS issue I have listed has been around for quite a while now. I think it's from October of last year. This is something that because they changed up the configuration with regards to a remote code execution vulnerability, 59287 from 2025, there's an error in the way the system reports synchronization. Be aware of that. I think that's something we're going to have to accept. I don't think that's anything that they're fixing or planning to fix at the moment. Windows 10, the long-term service branch, and obviously the associated servers that are still receiving full support. I have them listed here, 2016, 2022. 122 vulnerabilities, obviously, a lot of overlap with what we saw in Windows 11. None exploited or publicly disclosed in either of the major operating systems this month, which is great. There are some side issues, as you can expect, similar to what we saw on Windows 11. The WSUS issue occurs on the different server versions, and that BitLocker issue is also showing up on Server 2022. The certain versions of Windows 10, the ESU version, which is the Desktop 22H2, as well as the currently supported long-term service channels for 2021 and the IoT version for 2021. Those are showing up with that BitLocker issue, so be aware of those. That's what's new with those. Not a lot of issues, which is great. We did see an update. This is the first time since October for Microsoft.NET framework, 3.5 through 4.81. It was rated critical, which is unusual. Most of the.NET updates we've had in the past have been just important. But there were three CVEs addressed. I have them listed here. What's interesting is that when you dig into the bulletins for these, they actually list a lot more, several other additional CVEs. Most of them are denial of service, but there were a few elevation of privilege vulnerabilities as well, which is interesting that they didn't appear in the normal listing that Microsoft provides on their security page. But be aware of this. They did not release a standalone security-only update like they've done in the past. It appears that because the.NET versions are slowly approaching end-of-life, that they're only going to do a cumulative version. There were not any security-only, just the CVEs for this month. They are actually a roll-up with a lot of different vulnerabilities. Be aware of that, so you won't see a separate bulletin for security-only net this month. Moving on to Office. It's funny that they're continuing to support their end-of-life Office 2016, and I call that out here specifically. But we did see 11 vulnerabilities addressed this month across these different applications. Excel 2016, Office 2016, and PowerPoint 2016 got updates, as well as the handful of associated applications that go along with the old Office Suite, Office Online Server, which is going to be supported for two or three more years, I believe. We're continuing to get updates for the long-term service channel versions for Mac as well. Be aware of those. As far as the click-to-run online versions, one additional vulnerability, it's the first one here on the list of 23657, that was not covered in the regular Office updates, otherwise, they're all overlapping. There were 12 vulnerabilities this month that was rated critical. Make sure you include that in your Patch Tuesday updates as you go through your Office applications. Chris talked about SharePoint Server and the fact that we did have the one known escalated vulnerability. It's interesting, everything else is rated critical, but the one that has an exploited vulnerability is rated as important. Well, there you go, Microsoft. Thank you. That's one of the reasons that you don't necessarily want to use the rating system when you go through your patching process. You might want to look at it from CVSS scoring or some other approaches. Chris did mention all three supported versions of SharePoint Server have this issue, both the subscription edition, 2016 and 2019. No known issues around this does require an application restart, and there were a series of, it's a spoofing vulnerability, by the way. Finally, we did see two months in a row now, updates for SQL Server. Again, rated important this month, just one vulnerability in this one particular site. It's elevation of privilege vulnerability that we've covered here as well, and it's across all versions going all the way back to 2016. A lot of coverage there as far as that goes on the SQL Server side. Moving on to between the Patch Tuesdays. As we mentioned, a lot happens between Patch Tuesdays, not everything drops on Patch Tuesday. We had a record number of patches that came out since March. As a matter of fact, huge number of patches that came out with reported CVEs this month. Also, you can see all the number of security updates that we've released without CVEs. These are applications where the vendor says these have security fixes but don't call out specific CVEs. Then we have some things that are lumped into performance, bug fix, not specific to a CVE update, or a vulnerability update, or a security update for that given month. Going through these in a little bit of detail, I do call out the version numbers that were released here. I put our queue number, which is the ID specific to these patches for Mavavanti. 17 vulnerabilities in AutoCAD 2024. Chris was talking about the need for speed on patching some of these applications. I saw some questions as to what applications should we really put on the fast track to make sure that we update. If you notice here between the Patch Tuesdays, Google Chrome released six updates, not including what happened on the Patch Tuesdays. These are all security updates with vulnerabilities, not necessarily all zero days obviously, but you want to make sure that you do get those updates in place and have them on the fast track to keep up, especially on the browser side. Because guess what? Google Chrome, the Chromium is also used in Edge as well. You're going to see some of the same stuff on the Microsoft side. We saw an update for Devolutions Desktop Manager that included seven vulnerabilities. Docker for Windows, a lot of people use this on their servers, fixed one vulnerability. Additional browser updates here on the Firefox side. You can see those 46 vulnerabilities, five vulnerabilities there for that release. Their long-term or their extended support branches here, 4140.9 got updates as well. Foxit PDF Editor. I know a lot of us use this particular product. There are multiple versions available. The editor side, we saw a couple of updates here, seven vulnerabilities addressed, then we also see the subscription version. The reader enterprise version and consumer versions as well. We cover those in our catalog. Same vulnerabilities, by the way, across the list here. We did see a GIMP 3.2 update with five vulnerabilities. If you're using that, make sure you get updated. The Go language update, we saw 10 vulnerabilities addressed this month. Node.js, very common program that's used on the development side. We did see updates for current, we did see updates for LTS, long-term service upper versions. Our friend, Notepad++, many of us use that one vulnerability addressed. Python, did see three vulnerabilities addressed in the release this month. Red Hat, OpenJDK, a little bit delayed on this sometimes. Red Hat's a little slow sometimes to get out the updates from Oracle's releases, but they did address four vulnerabilities. Finally, on the e-mail side, we saw some Thunderbird updates. Both their regular version and their extended support version. A lot of overlap here because of the technology with their browser updates as well. You can see between the patch Tuesdays, a lot of activity, a lot of vulnerabilities addressed this month, much more than we've seen in the past. On the Apple side, keeping track here as well, there were updates on the operating system and browser side directly from Apple as well as from third-party vendors. We'll go through those here very quickly. We did see a Sonoma update. Obviously, Apple's model is to support the last three versions of their operating system. Tahoe being the latest, 26.4. They did have a name version change to come in line with what everybody else is doing with the year. This is 2026, obviously. They fixed 77 vulnerabilities there in their 26.4 release. Previous version was Sequoia 15.7.5, got 57, and Sonoma got actually the same set of vulnerabilities, very similar. They do provide separate updates for the browser, Safari on top of Sonoma and Sequoia. Eight vulnerabilities there if you're just doing a browser update from Apple. On the third-party side, again, here you see those same Google Chrome rollovers that we saw from the Windows side. Only four though this month, not six. They didn't cover all of them. Firefox, similar updates here, similar vulnerabilities as the Windows side. There are some that get dropped because they're not applicable on the Apple Mac OS operating system. There's a slight different number of identification here if you're actually going through and checking these things. Firefox updates as well, have them listed here very similar across the Windows side. Here we see all the Microsoft Edge updates. You'll see there's 30 vulnerabilities addressed there. One critical vulnerability, 3909, that was the zero day. You see all the Microsoft Edge updates. Here's 22 vulnerabilities, 18 vulnerabilities. Again, this is one that you might want to put on the fast track on the update side if you're doing weekly patching there. We did see a Teams update as well that came out. One thing that I found that was interesting is on Opera. You'll notice that this is not a typo. These actually were re-released multiple times for Opera. They ran into some problems. First of all, they backdated the fix. Then they ran into a problem with the fix and they included in newer versions of the updates. The same two vulnerabilities here were covered several times throughout multiple releases. They made changes and made some adjustments there. Make sure you're running the latest version of Opera. They finally got it right. Then of course, here we have the third-party versions. I mean, the Thunderbird version for Apple as well. Once again, e-mail side coverage there. We appreciate everybody joining us. This was a big one. We will definitely look forward to seeing you all again next month as well.

TL;DR

  • April 2026 delivered Microsoft's second-largest Patch Tuesday ever (159 CVEs) alongside critical zero-days in Adobe Reader and Google Chrome, requiring immediate response beyond traditional monthly patching cycles.
  • Anthropic's Project Mythos AI model will accelerate vulnerability discovery dramatically, particularly impacting open-source projects and forcing organizations to adopt parallel remediation tracks for different risk levels.
  • Microsoft is changing Office 365 update channels to monthly cadence starting July 2026, while Ivanti confirms Extended Security Update support for Windows Server 2016 post-end-of-life.
  • Third-party applications saw record patch activity with Google Chrome releasing six updates between Patch Tuesdays, emphasizing the need for weekly or daily update schedules for high-risk applications.
  • Organizations must shift from linear patch management to exposure management frameworks with separate tracks for regular maintenance, priority updates (browsers, collaboration tools), and zero-day response to minimize risk windows effectively.

Record-Breaking Patch Tuesday and Critical Zero-Days

April 2026 delivered Microsoft's second-largest Patch Tuesday in history with 159 CVEs addressed, surpassed only by October 2025's release. The month also saw critical zero-day vulnerabilities in Adobe Reader (CVE actively exploited since December) and Google Chrome's fourth zero-day of the year. The Adobe vulnerability is particularly severe—simply opening a malicious PDF triggers remote code execution with sandbox escape, prompting urgent deployment recommendations. Christopher Goettl and Todd Schell emphasize that organizations must move beyond monthly patching cycles to multi-track remediation strategies, with browser updates and high-risk applications requiring weekly or even daily update cadences to minimize exposure windows.

AI-Driven Vulnerability Discovery Reshaping Patch Management

Anthropic's Project Mythos represents a paradigm shift in vulnerability research, using sophisticated AI models to analyze codebases at unprecedented scale and speed. Goettl warns that open-source communities will face the greatest impact, as AI tools can identify vulnerabilities faster than maintainers can remediate them. This acceleration will force organizations to adopt exposure management frameworks rather than traditional linear patch processes. The webinar introduces Ivanti Neurons' parallel remediation approach: regular maintenance tracks for monthly updates, priority tracks for continuous-release applications like browsers, and zero-day response tracks for immediate threats. Organizations maintaining legacy systems like Windows Server 2016 will benefit from Ivanti's confirmed Extended Security Update (ESU) support, addressing strong customer demand revealed in recent surveys.

Microsoft 365 Channel Changes and Enterprise Impact

Starting July 2026, Microsoft will transition Office 365 update channels to a monthly cadence, requiring organizations to adjust their patch management workflows accordingly. The April release addressed 12 critical Office vulnerabilities, while SharePoint Server experienced an actively exploited spoofing vulnerability (rated 'important' despite active exploitation—highlighting the limitations of vendor severity ratings). SQL Server received updates for the second consecutive month, covering all versions back to 2016. The webinar also covered Microsoft's deprecation of the Recovery Assistant command-line tool (legacy from Windows XP era) in favor of the Get Help utility, with full transition required by October 2026. These changes underscore the need for organizations to monitor vendor roadmaps and adapt patch management processes to evolving release models.

Third-Party Application Security and Between-Patch Updates

Beyond Microsoft's releases, April saw record third-party patch activity with Google Chrome releasing six security updates between Patch Tuesdays, Firefox addressing 46 vulnerabilities across multiple releases, and critical updates for widely deployed tools like Docker, Node.js, Python, and Foxit PDF Editor. The Linux kernel continues showing increased CVE disclosures following the establishment of its dedicated CNA (CVE Numbering Authority), with three kernel vulnerabilities addressed this month. Apple released major updates for macOS Tahoe (26.4), Sequoia, and Sonoma, collectively addressing over 130 vulnerabilities. The presenters stress that organizations relying solely on monthly Patch Tuesday cycles are leaving significant exposure gaps—applications like browsers, development tools, and PDF readers require more frequent update schedules to maintain adequate security posture in today's threat landscape.

Chapters

0:00 - Webinar Introduction
2:01 - Zero-Day Exploits Overview
4:25 - Adobe Reader Zero-Day Details
6:33 - Google Chrome Fourth Zero-Day
7:07 - AI & Vulnerability Remediation
10:07 - Project Mythos Impact
21:32 - Windows Server 2016 ESU Support
23:02 - Microsoft Recovery Assistant Deprecation
23:45 - Defender & SharePoint Vulnerabilities
27:42 - Linux Kernel Vulnerabilities
35:12 - Microsoft Office Updates
42:17 - Office 365 Channel Changes
44:03 - Between Patch Tuesdays Updates
47:30 - Apple macOS Updates
49:40 - Webinar Conclusion

Key Quotes

0:07 "We had the second largest Patch Tuesday from Microsoft in history now. One-upped only by six CVEs from October last year."
5:50 "In this case, even just opening the PDF is enough to trigger the exploit from the reports that we've been seeing."
8:37 "Organizations that are doing more of their regular maintenance in that once a month track starting around Patch Tuesday, having certain applications like your browsers and your apps like Zoom or things like that that are highly easily user-targeted, happening more on a weekly basis, that priority updates track, they find that their risk window shrinks significantly."
22:42 "We will definitely have 2016 support. Just wanted to confirm that just to make sure everybody's aware."
26:56 "This one has been used in targeted attacks in the wild. The attacker who exploits this could view some sensitive information and even make changes to that disclosed information that they're able to get access to."
43:08 "It's interesting, everything else is rated critical, but the one that has an exploited vulnerability is rated as important. Well, there you go, Microsoft. Thank you. That's one of the reasons that you don't necessarily want to use the rating system when you go through your patching process."

FAQ

How should organizations adjust patching strategies in response to AI-driven vulnerability discovery?

Organizations need to move from linear monthly patch cycles to parallel remediation tracks: regular maintenance for monthly updates, priority tracks for continuous-release apps (browsers, collaboration tools) updated weekly or daily, and zero-day response tracks for immediate threats. This exposure management approach reduces risk windows significantly as AI tools like Anthropic's Mythos accelerate vulnerability discovery beyond traditional timelines.

What applications should be on accelerated patch schedules beyond monthly Patch Tuesday?

Browsers (Chrome, Edge, Firefox) should be updated weekly or daily given their frequent zero-day exploits—Chrome had four in 2026 alone. PDF readers like Adobe Reader, collaboration tools like Zoom and Teams, and development tools (Node.js, Python, Docker) also warrant priority tracks. Any application with continuous release models or high user exposure should be evaluated for more frequent patching than traditional monthly cycles.

Will Ivanti support Windows Server 2016 after its end-of-life date?

Yes, Ivanti will provide Extended Security Update (ESU) support for Windows Server 2016 post-end-of-life. This decision was driven by strong customer demand revealed in surveys, with many organizations indicating they will maintain 2016 footprints for at least the first year or longer. Ivanti has supported ESU programs since Windows NT4 and continues this commitment for customers requiring extended lifecycle management.


Categories:
  • » Webinar Library » Ivanti
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Webinar
  • Best Practices
  • Technical Deep Dive
  • Compliance & Governance
  • Cloud Security
  • AI & Machine Learning
  • Patch Tuesday
  • Zero-Day Vulnerabilities
  • AI-Driven Vulnerability Discovery
  • Exposure Management
  • Extended Security Updates
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Ivanti: April 2026 Patch Tuesday: Record Microsoft Updates & AI Threats

              Industry Events (Sponsor Hosted)

              • Aug
                03

                Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                08/03/202611:00 AM ET
                • Aug
                  06

                  Safeguarding Sensitive Data in the Era of Public AI Platforms

                  08/06/202604:00 AM ET
                  • Aug
                    06

                    Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks

                    08/06/202602:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/03/2026
                      11:00 AM
                      08/03/2026
                      Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                      https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Era of Public AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-public-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      Same Tactics, Enhanced Speed: AI Agents’ Impact on Identity Attacks
                      https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-speed-ai-agents-impact-on-identity-attacks/
                    • 08/07/2026
                      11:30 AM
                      08/07/2026
                      Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                      https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready: Insights and Strategies with Cyera
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version