April security patches for Windows: all the updates you should install

  • The April patches fix 167 vulnerabilities in Windows and other Microsoft products, including several zero-day vulnerabilities and eight critical ones.
  • The key updates are KB5083769 and KB5082052 for Windows 11 and KB5082200 for Windows 10 within ESU, all of them cumulative.
  • These updates are integrated into the official Patch Tuesday schedule, along with optional preview versions and out-of-band emergency patches.
  • It is essential to install security patches immediately, either through Windows Update or professional patch management tools, to reduce exposure to real attacks.

Windows security patches

If you use Windows daily for work, study, or simply browsing, the April security patches for Windows aren't just any update you can put off. This batch comes loaded with critical fixes, zero-day vulnerabilities, and key changes to how updates are distributed in both Windows 10 and Windows 11, including recent releases like 24H2 and 25H2.

In this article you will find everything you need to know about the April updates : which bugs they fix, which versions of Windows are involved, which specific packages (KB) you should look for, how they fit into the official Microsoft schedule (Patch Tuesdays, out-of-band releases, etc.) and how to update your PC safely , both from Windows Update and using professional patch management tools.

April security patches for Windows: what Microsoft has released

As it does every second Tuesday of the month, Microsoft has kept its traditional monthly update schedule and released a large package of security patches for much of its ecosystem: Windows, Office, server components, and tools like Defender and SharePoint Server. This April release is particularly noteworthy due to its size and the severity of some of the vulnerabilities it addresses.

This time, the company has patched 167 newly identified vulnerabilities , a very high number that includes two publicly known or actively exploited zero-day vulnerabilities, and eight vulnerabilities classified as critical. All of these patches are included in the regular cumulative updates for Windows 11 and in the specific patch for Windows 10 within the extended support programs.

Windows 11 systems receive updates KB5083769 for versions 24H2 and 25H2 and KB5082052 for Windows 11 23H2 , while Windows 10 users have access to the cumulative update KB5082200 through the ESU program . In all cases, these are monthly, cumulative security updates that include both recent fixes and those from previous months.

In addition to this month's changes, these updates add to other relevant patches that Microsoft has released in recent cycles, such as KB5071546 for Windows 10 and patches KB5072033 and KB5071417 for Windows 11 , which fixed 57 vulnerabilities, including several zero-day vulnerabilities, most notably the dangerous CVE-2025-54100 in PowerShell.

Breakdown of vulnerabilities fixed in April

The bulk of the April patches focus on strengthening the security of the operating system and multiple associated components. Microsoft has categorized the 167 vulnerabilities patched into several groups based on the type of attack they allow and the potential impact on Windows 10 and Windows 11 users.

First, 93 privilege escalation vulnerabilities stand out . These flaws are very popular among attackers because they are exploited when they have already managed to execute some type of malicious code on the system, but need to elevate their privileges to Administrator or even SYSTEM to disable defenses, move around the network, steal credentials, or leave persistent backdoors.

Thirteen vulnerabilities related to the bypassing of security features have also been fixed . These types of issues allow an attacker to circumvent protections designed to stop malware and intrusion attempts, such as integrity checks, security alerts, or controls like SmartScreen, thus increasing the likelihood of success for other attack techniques.

One of the most critical areas is comprised of the 20 remote code execution (RCE) vulnerabilities . These flaws allow an attacker to execute code on a computer without physical access, by exploiting exposed services, components that process content (files, packets, network traffic), or errors in how Windows handles certain data. In practice, an RCE vulnerability turns a PC into an ideal entry point for ransomware, Trojans, or massive malware campaigns.

In addition, 21 information disclosure vulnerabilities have been patched. These vulnerabilities allow for the leakage of data that should not be publicly available, ranging from internal system details to sensitive personal or corporate information. This type of flaw, in itself, poses a privacy problem, but it also serves to refine subsequent attacks, build more reliable exploits, or circumvent mitigations.

The list is completed by 10 denial-of-service (DoS) vulnerabilities , capable of taking a critical piece of equipment or service out of service, causing restarts, crashes or interruptions in activity, and 9 spoofing vulnerabilities , with which an attacker can pass off false resources or identities as legitimate and deceive both internal components of the system and the user himself.

Two Zero Day vulnerabilities and flaws in Office

Within the large April patch package , two zero-day vulnerabilities stand out in particular . These are security flaws for which active attacks or public information already existed before the patch was released. In these cases, there's minimal room for error: if you don't update quickly, your system could be vulnerable to real attacks already running on the network.

The first, identified as CVE-2026-32201 , is an identity spoofing vulnerability in Microsoft SharePoint Server . This flaw is considered especially critical because it has been confirmed to be actively exploited in real-world environments, making its patch a top priority for organizations using this product in their infrastructure.

The second zero-day vulnerability is CVE-2026-33825 , a privilege escalation issue in Microsoft Defender . This flaw allowed attackers to gain more privileges within the system by exploiting the security engine itself, something that has already been fixed through the updates included in this patch cycle.

In parallel, Microsoft has used the April release to patch several remote code execution vulnerabilities in Microsoft Office . Specifically, it corrects vulnerabilities affecting applications like Word and Excel, which could be exploited both by opening malicious documents and by viewing compromised files from the preview pane, making it even more likely to fall into the trap with a single click.

How do these patches fit into the official update schedule?

Beyond the specific vulnerabilities, it's important to understand how the April security patches for Windows fit into Microsoft's maintenance model. The updates you just received are part of the so-called monthly security update release , which is always published on the second Tuesday of each month, usually at 10:00 AM Pacific Time.

These releases are known by various names in documentation and technical jargon: Patch Tuesday, Quality Updates, LCU, or Week B. They all refer to the same thing: a cumulative release that includes new security fixes as well as non-security improvements that were tested in the previous month's optional preview.

Monthly security updates are cumulative , meaning they contain all previous fixes. Even if you haven't updated in a while, installing the latest update will include all the improvements from previous months. This is why most organizations consider them mandatory and base their security strategy on deploying them systematically.

These updates are available through Microsoft's usual channels, such as Windows Update, Windows Update for Business, and Windows Server Update Services (WSUS) . Management tools like Microsoft Configuration Manager and Intune rely on these channels to orchestrate patch distribution across corporate networks of all sizes.

Starting with Windows 11 version 24H2, Microsoft also introduced cumulative updates as checkpoints . The idea is that certain updates serve as a base, and subsequent updates only contain incremental improvements over that last checkpoint. For home users, the process remains the same: Windows Update continues to install the latest available update without you having to worry about which checkpoints have been applied previously.

Optional preview versions and out-of-band releases

In addition to the regular Patch Tuesday releases, the Windows update cycle includes optional preview versions that are not related to security . These are typically released on the fourth Tuesday of each month and allow administrators and advanced users to preview the changes that will be included in the next monthly security update.

These preview versions are also cumulative, but their installation is optional and they are usually offered only for the latest compatible versions of Windows. They are often labeled with names such as week D releases, preview updates, or LCU Preview . Among other things, they may include new features that are later consolidated in the next monthly security update.

In extraordinary situations, Microsoft resorts to out-of-band (OOB) releases . These are patches released outside the regular schedule to fix critical problems or serious vulnerabilities that can't wait for the next Patch Tuesday. Some of these releases are classified as critical and are automatically distributed through the usual channels, while others are considered non-critical and are only published in the Microsoft Update catalog for download by anyone who needs them.

A good recent example of this type of release was patch KB5066189 , published to fix a serious bug introduced by the August 2025 patches, which affected the Reset this PC feature in various editions of Windows 10 and Windows 11 (22H2 and 23H2). This bug could render data inaccessible when attempting to recover the system, so Microsoft opted for an out-of-box (OOB) emergency patch that completely replaced the problematic previous update.

In all cases, these out-of-band versions remain cumulative and replace any previous monthly security updates or preview versions, so simply installing the latest version is enough to be covered.

Continuous innovation and feature updates in Windows 11

Since Windows 11 version 22H2, Microsoft has opted for a model of continuous innovation . This means that not all improvements and new features wait for the major annual update: many are rolled out gradually through optional preview versions and, later, monthly security updates.

The logic is simple: first, new features are tested in an optional version installed only by those who explicitly choose to do so, and then, with further validation and telemetry, they are integrated into the stable branch of Windows through monthly updates. On systems managed by policies (for example, those managed with Intune, WSUS, or Configuration Manager), some new features are disabled by default until the next annual feature update is deployed.

For these corporate scenarios, there is a specific client policy that allows for the proactive activation of features that control temporary enterprise features. This way, each organization can decide when to activate certain new features without losing control over the stability of the environment.

Alongside this continuous innovation, Windows maintains its annual feature update cycle , which is released in the second half of the year. These updates change the major system version (for example, 25H2 or 26H2), are cumulative, and include both previous bug fixes and new features and performance improvements.

These annual updates also mark the start of the support cycle: 24 months for the Home and Pro editions and 36 months for the Enterprise and Education editions . A special case is Windows 11 26H1, which Microsoft has begun rolling out as a platform release focused on new AI hardware (for example, devices with Snapdragon X2 or high-end GPUs with NPUs); it's not a general update for everyone, but rather a compatibility base for that specific batch of devices.

Key recent patches: SharePoint, PowerShell, BitLocker, and more

The April patches fit into a sequence of recent updates where Microsoft has had to deal with multiple critical vulnerabilities and even problems caused by some previous updates. Understanding this context helps to appreciate why it's so important not to leave your system unpatched.

In addition to the previously mentioned CVE-2026-32201 (SharePoint Server) and CVE-2026-33825 (Defender), Microsoft has patched several high-profile vulnerabilities in previous months, such as CVE-2025-54100 in PowerShell , considered a high-risk vulnerability. This flaw allowed malicious code to be executed from websites simply by abusing the Invoke-WebRequest command , which has led to the introduction of an additional confirmation step in execution to curb automated attacks.

The patch package also addressed critical flaws in the network stack and core components : RCE vulnerabilities in the Reliable Multicast Transport (RMCAST) driver, the Windows TCP/IP protocol, HTTP headers, and the way certain Unicode sequences are processed. Connectivity errors with WPA3, problems related to Secure Boot, and a specific bug that caused some systems with System Guard Secure Launch and VSM to restart instead of shutting down or hibernating have also been resolved.

Another important patch, KB5041585 , addressed an issue with BitLocker recovery , which is critical if you rely on disk encryption to protect your computer's data. Keeping these security layers up to date is just as important as installing antivirus software or using strong passwords.

In the Office suite, in addition to the RCE (Real Community Environment) vulnerabilities in Word and Excel, several vulnerabilities affecting technologies such as MSHTML/Internet Explorer, OLE, and COM have been fixed . These older components are still present in some attack vectors. Some of these flaws were classified as zero-day vulnerabilities, with exploits already in circulation, reinforcing the message that delaying updates is not a good idea.

Windows 10 after the end of support and ESU programs

Although mainstream support for Windows 10 ended in October 2025 , Microsoft continues to release certain updates for this version through special channels. The most significant of these are those delivered via Extended Security Updates (ESU) , a paid extended support program aimed at businesses, government agencies, and organizations that need more time to migrate to Windows 11.

Within this framework, Windows 10 Enterprise LTSC editions also play an important role . These are designed for industrial environments, kiosks, embedded systems, or equipment that requires extreme stability and minimal changes over time. These editions have a distinct lifecycle, with extended support and a much more conservative update policy.

In this context, patches like KB5071546 for Windows 10 , which fixed 57 vulnerabilities, including three zero-day vulnerabilities, and the April cumulative update KB5082200 , which is part of the batch we're discussing, are relevant. Even though Windows 10 no longer receives new consumer features, it remains essential to apply critical security patches if your computer still relies on this version.

It's important to remember that Windows 10 maintains a market share of nearly 40% , making any unpatched vulnerabilities a highly attractive target for large-scale malware campaigns. This is why Microsoft has been compelled to continue providing essential fixes to these users, even outside of standard support, to prevent high-impact incidents.

What exactly are security patches and why are they so important?

Security patches are simply small pieces of code designed to fix security vulnerabilities, bugs, or compatibility issues in systems and applications. In the case of Windows, they usually arrive packaged as cumulative updates that are installed through Windows Update or centralized management tools.

Microsoft releases security updates on the second Tuesday of each month , the well-known Patch Tuesday, though it also releases out-of-band patches when a particularly critical vulnerability or serious bug requiring immediate attention appears. These updates may include performance improvements, minor new features, and bug fixes, in addition to strictly security fixes.

Delaying updates has a direct cost: the longer a system goes unupdated, the more exposed it becomes to known vulnerabilities . Cybercriminals analyze security bulletins and published patches to create exploits that target those who haven't updated, making an outdated PC an easy target.

Among the different types of Windows updates are critical patches, security updates, rollups, feature packs, definition updates, and service packs . Each has a specific purpose, but they all contribute to the common goal of strengthening the stability, compatibility, and security of the operating system.

In a professional setting, manually managing all these updates can be impractical, especially in networks with hundreds or thousands of devices. Therefore, it's common to use unified patch management solutions that automate the process, reduce human error, and ensure that all endpoints remain protected with minimal impact on productivity.

Professional patch management: Patch Manager Plus

For those who manage multiple Windows machines, tools like Patch Manager Plus greatly simplify the deployment of Microsoft security patches, including those released in April. These types of solutions combine the convenience of automation with granular control over what is installed, where, and when.

Patch Manager Plus offers two basic approaches to deploying Microsoft Windows updates : manual installation and automated deployment. In both cases, the administrator can filter by patch type (for example, security updates only), schedule installation times, select target computer groups, and configure notifications about the status of tasks.

In manual mode, the typical workflow involves going to the console, entering the deployment section, creating a patch installation or uninstallation task, assigning a name and description , adding the patches while filtering by update type (for example, Windows security only), specifying whether to schedule the execution for a specific date and time, and choosing the target computers. You can also define how to handle deployment failures and how to receive email alerts.

Automated Patch Deployment (APD) mode goes a step further, allowing the tool to continuously monitor new updates released by Microsoft. The administrator can create Windows-specific APD tasks, specify that security updates should be included, choose whether to patch all applications, only some, or exclude certain fixes, and set the priority based on severity (critical, important, moderate, low, or unrated).

In a second stage, the deployment policy is defined, adjusting the frequency, day of the week, and preferred time slot for installing updates. Next, the target computers are selected, and status notifications are configured to receive reports on each run. From then on, the process becomes virtually autonomous, reducing the time of exposure to newly discovered vulnerabilities.

How to install the April security patches from Windows Update

If you manage your own PC or a small number of computers, the easiest way is to use Windows Update , the built-in system tool. In most cases, the April security updates should have downloaded automatically and be waiting to install after a restart.

To check this in Windows 10 or Windows 11, simply open the Settings app from the Start menu or the gear icon in the notification panel and go to Update & Security (in Windows 10) or directly to the Windows Update section (in Windows 11). There you will see if there are any patches ready to install, usually with an Install now button.

If you still don't see anything, you can click on Check for updates to force a check against Microsoft's servers. Once the package corresponding to your version is detected (for example, KB5083769 for Windows 11 24H2/25H2, KB5082052 for 23H2, or KB5082200 for Windows 10 ESU), Windows will download the necessary files and prompt you to restart when the process is complete.

The download and installation process may take a few minutes, depending on your internet connection speed and the number of changes included in the update. During this time, you will see a progress bar in the Windows Update window. It is important not to abruptly shut down your computer while the patches are being installed, especially during restart, to avoid system damage.

If you prefer to download updates manually, or if you manage computers without a direct internet connection, you can always go to the Microsoft Update catalog and search for the KB number you need. From there, you can download the corresponding .msu file and install it manually on each PC.

In recent versions of Windows 11, you can also check the update history from Settings > Windows Update to see if the April patches have already been applied. This list should include names like KB5077181 or KB5075941 for previous Windows 11 patches, or KB5075912 for certain Windows 10 fixes, along with their installation date.

Ultimately, these April security patches for Windows, along with recent updates that have addressed zero-day vulnerabilities, PowerShell bugs, BitLocker issues, and flaws in critical features like Reset this PC, make it clear that keeping Windows up to date is no longer optional, but a basic security necessity . Taking a few minutes to check Windows Update or configure a good patch management policy is the difference between staying one step ahead of attackers and leaving the door open for them to exploit vulnerabilities that already have fixes.

Windows Update
Related article:
How to temporarily pause updates in Windows 10

Add as preferred source in Google