
Microsoft Patch Tuesday: April 2026
On 14 April 2026, Microsoft released its April 2026 security update, addressing 165 newly disclosed vulnerabilities. Among these, Arctic Wolf has highlighted two vulnerabilities in
Delivering security operations outcomes.
Collect, enrich, and analyse security data at scale.
Ecosystem integrations and technology partnerships.
Tailored security expertise and guided risk mitigation.
Security experts proactively protecting you 24×7.
Meet the security experts working alongside you and your team.
Learn how our IR team stops attacks and swiftly restores your organisation to pre-incident operations.
Address cyber risk end-to-end.
Map your security posture against industry standard frameworks.
Receive end-to-end IR coverage for one incident, no matter the incident type.
Engage and prepare employees to recognize and neutralize social engineering attacks.
Discover, assess, and harden your environment against digital risks.
AI-driven prevention, detection, and response to stop endpoint threats before they disrupt your business.
Quickly detect, respond, and recover from advanced threats.
Recover quickly from cyber attacks and breaches, from threat containment to business restoration.
Stay covered at no cost with up to $3M in financial assistance for cybersecurity incidents.
Increase the likelihood of insurability, and potentially lower your rates.
Access a complimentary suite of tools to reduce risk and improve insurability.
NIS2 Directive
NIS2 aims to make the EU as a whole more resilient to cyber threats and strengthen cooperation between Member States on cybersecurity.The Arctic Wolf State of Cybersecurity: 2025 Trends ReportThe Arctic Wolf State of Cybersecurity: 2025 Trends Report serves as an opportunity for decision makers to share their experiences over the past 12 months and their perspectives on some of the most important issues shaping the IT and security landscape.2025 Arctic Wolf Threat ReportThe Arctic Wolf Threat Report draws upon the first-hand experience of our security experts, augmented by research from our threat intelligence team. |

On 14 April 2026, Microsoft released its April 2026 security update, addressing 165 newly disclosed vulnerabilities. Among these, Arctic Wolf has highlighted two vulnerabilities in

On 10 March 2026, Progress ShareFile released fixes for two critical severity vulnerabilities in Progress ShareFile Storage Zones Controller (SZC) 5.x, tracked as CVE-2026-2699 and

The widely used Axios npm package, a JavaScript library that enables applications to make HTTP/S requests and is included as a dependency in millions of

On 28 March 2026, F5 updated its security advisory for a vulnerability impacting BIG-IP APM that was originally disclosed in October 2025 (CVE-2025-53521). The vulnerability

On 10 March 2026, Microsoft released its March 2026 security update addressing 83 newly disclosed vulnerabilities. Arctic Wolf has highlighted three vulnerabilities affecting Microsoft Office

On 03 March 2026, pac4j released fixes for a maximum severity vulnerability in pac4j-jwt, tracked as CVE-2026-29000. The flaw arises from improper verification of cryptographic

On 24 February 2026, sooperset, the mcp-atlassian project maintainer, released fixes?for a critical vulnerability in?mcp-atlassian, tracked as CVE-2026-27825. The flaw arises from missing directory confinement

On 25 February 2026, Cisco released fixes for a maximum severity authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN

Update: Arctic Wolf has observed suspected exploitation of CVE-2026-1731 and has published its findings in an updated security bulletin, available here.? Since our previous security

On 10 February 2026, Microsoft?released its February 2026 security update, addressing 59 newly disclosed vulnerabilities.?Arctic Wolf highlighted six of these vulnerabilities?affecting Microsoft Windows and Microsoft

On 6 February 2026, Fortinet released fixes for a critical vulnerability in FortiClientEMS, tracked as CVE-2026-21643. The flaw arises from improper neutralisation of special elements

On 6 February 2026, BeyondTrust released fixes for a critical vulnerability affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA), tracked as CVE?2026?1731. This

On 2 February 2026, the Notepad++ open source project disclosed?new details?about a supply chain compromise that?impacted?its update delivery infrastructure between June and December 2025. The

On 29 January 2026, Ivanti released fixes for two critical zero-day code injection vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM). The vulnerabilities, tracked as CVE-2026-1281

Summary On 27 January 2026, Fortinet released an advisory detailing a critical authentication bypass vulnerability affecting FortiOS, FortiAnalyzer, FortiManager, and FortiProxy products. Designated CVE-2026-24858, the

On 28 January 2026, SolarWinds?released fixes for multiple vulnerabilities?impacting?Web Help Desk (WHD). WHD is an IT service management platform that may?contain?sensitive information, making it a

On 20 January 2026, Oracle patched a maximum?severity vulnerability in its Fusion Middleware suite affecting Oracle HTTP Server and the WebLogic Server Proxy Plug?in, tracked

On 21 January 2026, Cisco released fixes for a high-severity vulnerability impacting Cisco Unified Communications products that is under active exploitation, tracked as CVE-2026-20045. The

On 13 January 2025, Fortinet released?fixes for a critical-severity?FortiSIEM?vulnerability (CVE-2025-64155) that stems from improper neutralization of special elements used in OS commands within the?phMonitor?service (TCP/7900).

On 13 January 2026, Fortinet released an advisory?describing a high-severity remote code execution vulnerability affecting its?FortiOS?and?FortiSwitchManager?products. According to Fortinet, the vulnerability stems from a flaw

On 13 January Microsoft released its January 2026 security update, addressing 112 newly disclosed vulnerabilities. Arctic Wolf has highlighted four vulnerabilities affecting Microsoft Windows and

On 7 January 2026, Trend Micro released?a critical patch for Apex Central on-premises?versions below Build 7190, addressing multiple vulnerabilities. The most severe of the vulnerabilities?disclosed?is

On 7 January 2026, fixes?were released for a maximum severity vulnerability (CVE-2026-21858)?impacting?n8n, a workflow automation application primarily used with artificial intelligence. Labeled ¡°Ni8mare¡± by the

On 19 December 2025, MongoDB issued an advisory?for CVE-2025-14847, known as ¡°MongoBleed,¡± a high-severity vulnerability in the server¡¯s?zlib-based network compression functionality. This vulnerability affects how

On 17 December 2025, Cisco published an advisory?detailing a new threat campaign?identified?on December 10,?affecting the Cisco?AsyncOS?software used on Cisco Secure Email Gateway and Cisco Secure

On 17 December 2025, SonicWall released fixes for an actively exploited medium-severity zero-day vulnerability in the SonicWall SMA1000 Appliance Management Console (AMC), tracked as CVE-2025-40602.

On 12 December 2025, Arctic Wolf began observing intrusions involving malicious SSO logins on FortiGate appliances. Fortinet had previously released an advisory for two critical

On 9 December 2025, Microsoft released its December 2025 security update, addressing 57 newly disclosed vulnerabilities. Arctic Wolf has highlighted three vulnerabilities?affecting Microsoft Windows and

On 3 December 2025, the React team released fixes for a maximum severity vulnerability in React Server Components (RSC). The vulnerability, tracked as CVE-2025-55182, stems

On 19 November 2025, Salesforce announced?an?investigation into?unusual activity involving applications published by Gainsight, a company that provides customer success software integrated with Salesforce. In their
EMEA HEADQUARTERS
? 2026 ºÚÁÏÉç. All Rights Reserved. |
|||||||
Privacy Notice |
Terms of Use |
Cookie Policy |
Customer Portal Policy |
Accessibility Statement |
Sustainability Statement |
Information Security |
Cookies Settings |