Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
    Cybersecurity

    April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More

    adminBy adminApril 16, 2026No Comments4 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 15, 2026Vulnerability / Data Breach

    A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April’s Patch Tuesday releases.

    Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database commands.

    “The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed,” Onapsis said in an advisory.

    In a potential attack scenario, a bad actor could abuse the affected upload-related functionality to run malicious SQL against BW/BPC data stores, extract sensitive data, and delete or corrupt database content.

    “Manipulated planning figures, broken reports, or deleted consolidation data can undermine close processes, executive reporting, and operational planning,” Pathlock said. “In the wrong hands, this issue also creates a credible path to both stealthy data theft and overt business disruption.”

    Another security vulnerability that deserves a mention is a critical-severity remote code execution in Adobe Acrobat Reader (CVE-2026-34621, CVSS score: 8.6) that has come under active exploitation in the wild.

    That said, there are many unknowns at this stage. It is not clear how many people have been affected by the hacking campaign. Nor is there any information about who is behind the activity, who is being targeted, and what their motives could be.

    Also patched by Adobe are five critical flaws in ColdFusion versions 2025 and 2023 that, if successfully exploited, could lead to arbitrary code execution, application denial-of-service, arbitrary file system read, and security feature bypass.

    The vulnerabilities are listed below –

    • CVE-2026-34619 (CVSS score: 7.7) – A path traversal vulnerability leading to security feature bypass
    • CVE-2026-27304 (CVSS score: 9.3) – An improper input validation vulnerability leading to arbitrary code execution
    • CVE-2026-27305 (CVSS score: 8.6) – A path traversal vulnerability leading to arbitrary file system read
    • CVE-2026-27282 (CVSS score: 7.5) – An improper input validation vulnerability leading to security feature bypass
    • CVE-2026-27306 (CVSS score: 8.4) – An improper input validation vulnerability leading to arbitrary code execution

    Fixes have also been released for two critical FortiSandbox vulnerabilities that could result in authentication bypass and code execution –

    • CVE-2026-39813 (CVSS score: 9.1) – A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. (Fixed in versions 4.4.9 and 5.0.6)
    • CVE-2026-39808 (CVSS score: 9.1) – An operating system command injection vulnerability in FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. (Fixed in version 4.4.9)

    The development comes as Microsoft addressed a staggering 169 security defects, including a spoofing vulnerability impacting Microsoft SharePoint Server (CVE-2026-32201, CVSS score: 6.5) that could allow an attacker to view sensitive information. The company said it’s being actively exploited, although there are no insights into the in-the-wild exploitation associated with the bug.

    “SharePoint services, especially those used as internal document stores, can be a treasure trove for threat actors looking to steal data, especially data that may be leveraged to force ransom payments using double extortion techniques by threatening to release the stolen data if payment is not made,” Kev Breen, senior director of threat research at Immersive, said.

    “A secondary concern is that threat actors with access to SharePoint services could deploy weaponised documents or replace legitimate documents with infected versions that would allow them to spread to other hosts or victims moving laterally across the organization.”

    Software Patches from Other Vendors

    In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including —

    • ABB
    • Amazon Web Services
    • AMD
    • Apple
    • ASUS
    • AVEVA
    • Broadcom (including VMware)
    • Canon
    • Cisco
    • Citrix
    • CODESYS
    • D-Link
    • Dassault Systèmes
    • Dell
    • Devolutions
    • dormakaba
    • Drupal
    • Elastic
    • F5
    • Fortinet
    • Foxit Software
    • FUJIFILM
    • Gigabyte
    • GitLab
    • Google Android and Pixel
    • Google Chrome
    • Google Cloud
    • Grafana
    • Hitachi Energy
    • HP
    • HP Enterprise (including Aruba Networking and Juniper Networks)
    • Huawei
    • IBM
    • Ivanti
    • Jenkins
    • Lenovo
    • Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu
    • MediaTek
    • Mitel
    • Mitsubishi Electric
    • MongoDB
    • Moxa
    • Mozilla Firefox, Firefox ESR, and Thunderbird
    • NETGEAR
    • Node.js
    • NVIDIA
    • ownCloud
    • Palo Alto Networks
    • Phoenix Contact
    • Progress Software
    • QNAP
    • Qualcomm
    • Rockwell Automation
    • Ruckus Wireless
    • Samsung
    • Schneider Electric
    • Siemens
    • SonicWall
    • Splunk
    • Spring Framework
    • Supermicro
    • Synology
    • TP-Link
    • WatchGuard, and
    • Xiaomi
    Adobe April Critical fixes Flaws Fortinet Microsoft Patch SAP Tuesday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleYouTube Premium is now 50% off for certain Google One subscribers
    Next Article Raspberry Pi OS is getting a new security measure, and people are already annoyed
    admin
    • Website

    Related Posts

    Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

    April 20, 2026

    Apple account change alerts abused to send phishing emails

    April 19, 2026

    Social media bans might steer kids into riskier corners of the internet

    April 19, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    CachyOS just shipped Linux 7.0, and it has some extra performance tweaks added to the mix

    April 20, 2026

    Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

    April 20, 2026

    Galaxy S26 Ultra vs Galaxy S23 Ultra – Is it FINALLY time to upgrade? [Video]

    April 20, 2026

    That screenless Google band on Stephen Curry’s wrist may finally have a name

    April 20, 2026
    Categories
    • Blogging (65)
    • Cybersecurity (1,404)
    • Privacy & Online Earning (172)
    • SEO & Digital Marketing (850)
    • Tech Tools & Mobile / Apps (1,690)
    • WiFi / Internet & Networking (232)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    CachyOS just shipped Linux 7.0, and it has some extra performance tweaks added to the mix

    April 20, 2026

    Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

    April 20, 2026

    Galaxy S26 Ultra vs Galaxy S23 Ultra – Is it FINALLY time to upgrade? [Video]

    April 20, 2026
    Most Popular
    • CachyOS just shipped Linux 7.0, and it has some extra performance tweaks added to the mix
    • Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
    • Galaxy S26 Ultra vs Galaxy S23 Ultra – Is it FINALLY time to upgrade? [Video]
    • That screenless Google band on Stephen Curry’s wrist may finally have a name
    • Starbucks’ New ChatGPT Integration Is a Potential Privacy Nightmare
    • I replaced my entire streaming setup with a $30 device and free apps
    • Blood Strike – FPS for all 1.003.650015 APK Download by NetEase Games
    • The Ray-Ban Meta (Gen 1) smart glasses just scored a rare 25% discount at Amazon
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.