April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More

The April Patch Tuesday releases address critical security vulnerabilities across major platforms, including actively exploited flaws in Microsoft and Adobe products.
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases.
Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database commands.
"The vulnerable ABAP program allows a low-privileged user to upload a file with arbitrary SQL statements that will then be executed," Onapsis said in an advisory.
In a potential attack scenario, a bad actor could abuse the affected upload-related functionality to run malicious SQL against BW/BPC data stores, extract sensitive data, and delete or corrupt database content.
Another security vulnerability that deserves a mention is a critical-severity remote code execution in Adobe Acrobat Reader (CVE-2026-34621, CVSS score: 8.6) that has come under active exploitation in the wild.
Also patched by Adobe are five critical flaws in ColdFusion versions 2025 and 2023 that, if successfully exploited, could lead to arbitrary code execution, application denial-of-service, arbitrary file system read, and security feature bypass.
Fixes have also been released for two critical FortiSandbox vulnerabilities (CVE-2026-39813 and CVE-2026-39808, both CVSS 9.1) that could result in authentication bypass and code execution.
The development comes as Microsoft addressed a staggering 169 security defects, including a spoofing vulnerability impacting Microsoft SharePoint Server (CVE-2026-32201, CVSS score: 6.5) that is being actively exploited. Experts warn that SharePoint services can be a treasure trove for threat actors looking to steal data for ransom or lateral movement within an organization.
In addition to these major vendors, dozens of other software and hardware providers including Apple, Cisco, Google, and various Linux distributions have also released critical security updates over the past several weeks.
Source: The Hacker News















