Sunday, September 13, 2026Analysis · Ideas · Culture
Educa-eco

AI & ML

Key Vulnerabilities of April 2026: A Closer Look at Cybersecurity Threats

Published May 15, 2026387 readers

April 2026 saw 37 high-impact vulnerabilities, highlighting an increase in exploit activity and a pressing need for immediate remediation efforts in cybersecurity.

Key Vulnerabilities of April 2026: A Closer Look at Cybersecurity Threats

April 2026 marked an uptick in cybersecurity threats, with Insikt Group® identifying 37 critical vulnerabilities that warrant urgent attention. Remarkably, 35 of these vulnerabilities achieved a Very Critical Recorded Future Risk Score, reflecting a 19% rise compared to March.

Of the 37 listed vulnerabilities, 31 were included in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog, highlighting their widespread impact. Six additional vulnerabilities were revealed through honeypot data, exclusively available to Recorded Future clients.

These vulnerabilities spanned products from 23 different vendors, with Microsoft representing about 22% of the total exposure. Remaining vulnerabilities primarily affected various enterprise-focused vendors, particularly those involved in security and systems management, collaboration platforms, server applications, and network-edge infrastructure.

In response to the escalating threat landscape, Insikt Group has developed Nuclei templates aimed at identifying specific missing authentication vulnerabilities found in Nginx UI (CVE-2026-33032) and Marimo (CVE-2026-39987). These templates are also available to logged-in Recorded Future customers.

Vulnerability Overview for April 2026

Among the vulnerabilities listed, all 31 actively exploited in April are summarized below; however, they do not include the six CVEs connected to honeypot data. The details provided feature examples of public proof-of-concept (PoC) identification, which have not undergone verification for effectiveness. Vulnerability management teams should verify PoCs independently before any testing occurs.

#
Vulnerability
Risk
Score
Vendor/Product
KEV
Malware Analysis
RCE
PoC
1
CVE-2009-0238
99
Microsoft Office Excel, Excel Viewer, Office Compatibility Pack, Office

(available to Recorded Future Customers)

2
CVE-2012-1854
99
Microsoft Office, Visual Basic for Applications
3
CVE-2020-9715
99
Adobe Acrobat, Acrobat Reader
4
CVE-2023-21529
99
Microsoft Exchange Server
5
CVE-2023-27351
99
PaperCut NG, MF
6
CVE-2023-36424
99
Microsoft Windows Server
7
CVE-2024-1708
99
ConnectWise ScreenConnect
8
CVE-2024-27199
99
JetBrains TeamCity On-Premises
9
CVE-2024-57726
99
SimpleHelp remote support software
10
CVE-2024-57728
99
SimpleHelp remote support software
11
CVE-2024-7399
99
Samsung MagicINFO Server
12
CVE-2025-2749
99
Kentico Xperience
13
CVE-2025-29635
99
D-Link DIR-823X
14
CVE-2025-32975
99
Quest KACE Systems Management Appliance
15
CVE-2025-48700
99
Synacor Zimbra Collaboration Suite (ZCS)
16
CVE-2025-60710
99
Windows Server Host Process for Windows Tasks
17
CVE-2026-1340
99
Ivanti Endpoint Manager Mobile
18
CVE-2026-20122
99
Cisco Catalyst SD-WAN Manager
19
CVE-2026-20128
99
Cisco Catalyst SD-WAN Manager
20
CVE-2026-20133
99
Cisco Catalyst SD-WAN Manager
21
CVE-2026-21643
99
Fortinet FortiClient EMS
22
CVE-2026-32201
99
Microsoft SharePoint Server
23
CVE-2026-32202
99
Windows Shell
24
CVE-2026-33825
99
Microsoft Defender

(available to Recorded Future Customers)

25
CVE-2026-34197
99
Apache ActiveMQ, ActiveMQ Broker
26
CVE-2026-34621
99
Adobe Acrobat, Acrobat Reader
27
CVE-2026-35616
99
Fortinet FortiClient EMS
28
CVE-2026-39987
99
Marimo
29
CVE-2026-41940
99
cPanel, WHM, WP Squared
30
CVE-2026-3502
89
TrueConf Client
31
CVE-2026-5281
89
Dawn in Google Chrome

Table 1: Summary of vulnerabilities actively exploited in April, based on data from Recorded Future (excluding those from honeypot sources).

Notable Trends in Vulnerability Exploitation

  • The month of April 2026 witnessed that seven of the reported 37 vulnerabilities were linked to ransomware activities.
    • Six of these were directly associated with Storm-1175's Medusa ransomware operations.
    • CISA also identified CVE-2026-41940 as being involved in known ransomware exploits (reported by Sorry Ransomware).
    • Moreover, the CVE-2024-3721 vulnerability found in TBK DVR devices has been exploited to spread the Nexcorium botnet.
  • Sixteen of the vulnerabilities allowed for remote code execution (RCE), impacting products from 12 vendors including Adobe, Fortinet, and Microsoft.
  • Proof-of-concept (PoC) exploit examples for 24 out of the 37 vulnerabilities were identified.
  • CWE-22 (Path Traversal) emerged as the most exploited flaw, followed by CWE-94 (Code Injection), CWE-20 (Improper Input Validation), and CWE-306 (Missing Authentication).
  • Three vulnerabilities have been around for over five years, and the oldest dates back approximately seventeen years, proving that long-standing weaknesses continue to be a target for attackers. The rapidity of exploitations is concerning, with some vulnerabilities showing a mere two-day window between public disclosure and exploitation.

Highlighting Exploitation Dynamics

Included herein is an examination of some of the most impactful vulnerabilities this month, particularly those associated with documented threat actor campaigns or those for which proof-of-concept exploits are publicly available. Vulnerabilities lacking significant technical details are summarized in the disclosures table only.

Exploiting TBK DVR Vulnerability for Botnet Deployment

On April 17, 2026, a report by FortiGuard Labs (@FortiGuardLabs) linked ongoing exploitation of TBK Model DVRs to the Nexcorium botnet, identified as a variant of the Mirai botnet. These DVR units are designed for security camera usage and storage. The vulnerability CVE-2024-3721 pertains to an OS command injection flaw, allowing attackers to execute arbitrary system commands remotely.

The exploit begins with crafted requests that manipulate parameters within TBK DVRs, leading to the deployment of a downloader script named dvr, which retrieves and executes the Nexcorium binaries. Detailed analysis and indicators of compromise (IoCs) related to this campaign are available to Recorded Future clients through Insikt Group reporting.

For further insights, Recorded Future customers can access Malware Intelligence resources for detailed investigations into linked network indicators.

Figure 1: Vulnerability Intelligence Card® for CVE-2024-3721 in Recorded Future
Figure 1: Vulnerability Intelligence Card® for CVE-2024-3721 in Recorded Future.
Source: John Johnson · www.recordedfuture.com

Discussion

Sign in to join the discussion.