SANS Stormcast Wednesday, April 15th, 2026: Microsoft, Adobe, Fortinet and others Patches
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 April 2026
⏱️ 9 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, April 15th, |
| 0:07.5 | 2006 edition of the Sands Internet Storm Center's Stormcast. |
| 0:12.4 | My name is Johannes Ulrich, and today I'm recording from Stockholm, Germany. |
| 0:17.5 | And this episode is brought you by the Sands.edu undergraduate certificate program in cybersecurity fundamentals. |
| 0:25.9 | Well, of course, no surprise today. We're starting with Microsoft's patch Tuesday for April. |
| 0:32.1 | And this is a little interesting patch Tuesday when I first looked at the number of vulnerabilities patch that was quite surprised. |
| 0:39.2 | According to our account, we have 243 vulnerabilities. But remember, our account also includes any Microsoft Edge vulnerabilities, which were actually already patched before today. |
| 0:51.2 | These are vulnerabilities in the underlying chromium browser that are then ported |
| 0:56.4 | into Microsoft Edge as well. So after we subtract these 78 vulnerabilities, we're left with |
| 1:03.5 | 165 vulnerabilities that are affecting Microsoft's own products, which is still a pretty solid |
| 1:10.7 | number. |
| 1:11.8 | Now, there are a couple of noteworthy ones here. |
| 1:14.6 | First of all, there are eight critical ones, and one that's already being exploited, |
| 1:19.2 | and one that hasn't been exploited yet, but, well, has become known before today. |
| 1:25.0 | The one that has become known before today, I may have mentioned, but it sort of came |
| 1:30.7 | out, I think, last week. And this is approach escalation in Microsoft Defender. One of those |
| 1:37.5 | typical sort of no antivirus vulnerabilities where basically an attacker can escalate privileges because, well, antivirus has |
| 1:46.5 | to operate at elevated privileges. The one that's already being exploited is then Microsoft |
| 1:55.1 | SharePoint spoofing vulnerability. There are actually two very similar SharePoint server spoofing vulnerabilities |
| 2:01.9 | that are being patched this month, but only one of them is already being exploited. |
| 2:08.9 | Now, other sort of interesting vulnerabilities, but basically critical vulnerabilities, |
| 2:13.1 | the one that sort of caught my eye first, that I think is sort of the most interesting one, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

