April 2026 saw 37 high-impact vulnerabilities, highlighting an increase in exploit activity and a pressing need for immediate remediation efforts in cybersecurity.

April 2026 marked an uptick in cybersecurity threats, with Insikt Group® identifying 37 critical vulnerabilities that warrant urgent attention. Remarkably, 35 of these vulnerabilities achieved a Very Critical Recorded Future Risk Score, reflecting a 19% rise compared to March.
Of the 37 listed vulnerabilities, 31 were included in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog, highlighting their widespread impact. Six additional vulnerabilities were revealed through honeypot data, exclusively available to Recorded Future clients.
These vulnerabilities spanned products from 23 different vendors, with Microsoft representing about 22% of the total exposure. Remaining vulnerabilities primarily affected various enterprise-focused vendors, particularly those involved in security and systems management, collaboration platforms, server applications, and network-edge infrastructure.
In response to the escalating threat landscape, Insikt Group has developed Nuclei templates aimed at identifying specific missing authentication vulnerabilities found in Nginx UI (CVE-2026-33032) and Marimo (CVE-2026-39987). These templates are also available to logged-in Recorded Future customers.
Vulnerability Overview for April 2026
Among the vulnerabilities listed, all 31 actively exploited in April are summarized below; however, they do not include the six CVEs connected to honeypot data. The details provided feature examples of public proof-of-concept (PoC) identification, which have not undergone verification for effectiveness. Vulnerability management teams should verify PoCs independently before any testing occurs.
Score
✓
(available to Recorded Future Customers)
Table 1: Summary of vulnerabilities actively exploited in April, based on data from Recorded Future (excluding those from honeypot sources).
Notable Trends in Vulnerability Exploitation
- The month of April 2026 witnessed that seven of the reported 37 vulnerabilities were linked to ransomware activities.
- Six of these were directly associated with Storm-1175's Medusa ransomware operations.
- CISA also identified CVE-2026-41940 as being involved in known ransomware exploits (reported by Sorry Ransomware).
- Moreover, the CVE-2024-3721 vulnerability found in TBK DVR devices has been exploited to spread the Nexcorium botnet.
- Sixteen of the vulnerabilities allowed for remote code execution (RCE), impacting products from 12 vendors including Adobe, Fortinet, and Microsoft.
- Proof-of-concept (PoC) exploit examples for 24 out of the 37 vulnerabilities were identified.
- CWE-22 (Path Traversal) emerged as the most exploited flaw, followed by CWE-94 (Code Injection), CWE-20 (Improper Input Validation), and CWE-306 (Missing Authentication).
- Three vulnerabilities have been around for over five years, and the oldest dates back approximately seventeen years, proving that long-standing weaknesses continue to be a target for attackers. The rapidity of exploitations is concerning, with some vulnerabilities showing a mere two-day window between public disclosure and exploitation.
Highlighting Exploitation Dynamics
Included herein is an examination of some of the most impactful vulnerabilities this month, particularly those associated with documented threat actor campaigns or those for which proof-of-concept exploits are publicly available. Vulnerabilities lacking significant technical details are summarized in the disclosures table only.
Exploiting TBK DVR Vulnerability for Botnet Deployment
On April 17, 2026, a report by FortiGuard Labs (@FortiGuardLabs) linked ongoing exploitation of TBK Model DVRs to the Nexcorium botnet, identified as a variant of the Mirai botnet. These DVR units are designed for security camera usage and storage. The vulnerability CVE-2024-3721 pertains to an OS command injection flaw, allowing attackers to execute arbitrary system commands remotely.
The exploit begins with crafted requests that manipulate parameters within TBK DVRs, leading to the deployment of a downloader script named dvr, which retrieves and executes the Nexcorium binaries. Detailed analysis and indicators of compromise (IoCs) related to this campaign are available to Recorded Future clients through Insikt Group reporting.
For further insights, Recorded Future customers can access Malware Intelligence resources for detailed investigations into linked network indicators.
Discussion
Sign in to join the discussion.