By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
Computing

April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More

News Room
Last updated: 2026/04/15 at 10:38 AM
News Room Published 15 April 2026
Share
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
SHARE

Ravie LakshmananApr 15, 2026Vulnerability / Data Breach

A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April’s Patch Tuesday releases.

Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database commands.

“The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed,” Onapsis said in an advisory.

In a potential attack scenario, a bad actor could abuse the affected upload-related functionality to run malicious SQL against BW/BPC data stores, extract sensitive data, and delete or corrupt database content.

“Manipulated planning figures, broken reports, or deleted consolidation data can undermine close processes, executive reporting, and operational planning,” Pathlock said. “In the wrong hands, this issue also creates a credible path to both stealthy data theft and overt business disruption.”

Another security vulnerability that deserves a mention is a critical-severity remote code execution in Adobe Acrobat Reader (CVE-2026-34621, CVSS score: 8.6) that has come under active exploitation in the wild.

That said, there are many unknowns at this stage. It is not clear how many people have been affected by the hacking campaign. Nor is there any information about who is behind the activity, who is being targeted, and what their motives could be.

Also patched by Adobe are five critical flaws in ColdFusion versions 2025 and 2023 that, if successfully exploited, could lead to arbitrary code execution, application denial-of-service, arbitrary file system read, and security feature bypass.

The vulnerabilities are listed below –

  • CVE-2026-34619 (CVSS score: 7.7) – A path traversal vulnerability leading to security feature bypass
  • CVE-2026-27304 (CVSS score: 9.3) – An improper input validation vulnerability leading to arbitrary code execution
  • CVE-2026-27305 (CVSS score: 8.6) – A path traversal vulnerability leading to arbitrary file system read
  • CVE-2026-27282 (CVSS score: 7.5) – An improper input validation vulnerability leading to security feature bypass
  • CVE-2026-27306 (CVSS score: 8.4) – An improper input validation vulnerability leading to arbitrary code execution

Fixes have also been released for two critical FortiSandbox vulnerabilities that could result in authentication bypass and code execution –

  • CVE-2026-39813 (CVSS score: 9.1) – A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. (Fixed in versions 4.4.9 and 5.0.6)
  • CVE-2026-39808 (CVSS score: 9.1) – An operating system command injection vulnerability in FortiSandbox that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. (Fixed in version 4.4.9)

The development comes as Microsoft addressed a staggering 169 security defects, including a spoofing vulnerability impacting Microsoft SharePoint Server (CVE-2026-32201, CVSS score: 6.5) that could allow an attacker to view sensitive information. The company said it’s being actively exploited, although there are no insights into the in-the-wild exploitation associated with the bug.

“SharePoint services, especially those used as internal document stores, can be a treasure trove for threat actors looking to steal data, especially data that may be leveraged to force ransom payments using double extortion techniques by threatening to release the stolen data if payment is not made,” Kev Breen, senior director of threat research at Immersive, said.

“A secondary concern is that threat actors with access to SharePoint services could deploy weaponised documents or replace legitimate documents with infected versions that would allow them to spread to other hosts or victims moving laterally across the organization.”

Software Patches from Other Vendors

In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including —

  • ABB
  • Amazon Web Services
  • AMD
  • Apple
  • ASUS
  • AVEVA
  • Broadcom (including VMware)
  • Canon
  • Cisco
  • Citrix
  • CODESYS
  • D-Link
  • Dassault Systèmes
  • Dell
  • Devolutions
  • dormakaba
  • Drupal
  • Elastic
  • F5
  • Fortinet
  • Foxit Software
  • FUJIFILM
  • Gigabyte
  • GitLab
  • Google Android and Pixel
  • Google Chrome
  • Google Cloud
  • Grafana
  • Hitachi Energy
  • HP
  • HP Enterprise (including Aruba Networking and Juniper Networks)
  • Huawei
  • IBM
  • Ivanti
  • Jenkins
  • Lenovo
  • Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu
  • MediaTek
  • Mitel
  • Mitsubishi Electric
  • MongoDB
  • Moxa
  • Mozilla Firefox, Firefox ESR, and Thunderbird
  • NETGEAR
  • Node.js
  • NVIDIA
  • ownCloud
  • Palo Alto Networks
  • Phoenix Contact
  • Progress Software
  • QNAP
  • Qualcomm
  • Rockwell Automation
  • Ruckus Wireless
  • Samsung
  • Schneider Electric
  • Siemens
  • SonicWall
  • Splunk
  • Spring Framework
  • Supermicro
  • Synology
  • TP-Link
  • WatchGuard, and
  • Xiaomi

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Spotify now sells physical books Spotify now sells physical books
Next Article Ordnance Survey works with Snowflake to tackle flood risk | Computer Weekly Ordnance Survey works with Snowflake to tackle flood risk | Computer Weekly
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The AI Grid Is Leaving Earth
The AI Grid Is Leaving Earth
News
Ukraine’s enhanced fortifications are increasing the cost of Putin’s invasion
Ukraine’s enhanced fortifications are increasing the cost of Putin’s invasion
News
Replace Expensive Cloud Subscriptions With a One-Time 5TB Storage Solution, Now 80% Off
Replace Expensive Cloud Subscriptions With a One-Time 5TB Storage Solution, Now 80% Off
News
Social Media Analytics Tools for Better Marketing Insights |
Computing

You Might also Like

Social Media Analytics Tools for Better Marketing Insights |

7 Min Read
Nobody Is QA Testing Their LLM Apps (That’s Going to Be a Problem) | HackerNoon
Computing

Nobody Is QA Testing Their LLM Apps (That’s Going to Be a Problem) | HackerNoon

19 Min Read
n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails
Computing

n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails

5 Min Read
GeekWire Awards: Young Entrepreneur of the Year finalists tackling AI, robotics, and more
Computing

GeekWire Awards: Young Entrepreneur of the Year finalists tackling AI, robotics, and more

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?