MONTHLY FALLOUT REPORT

APRIL 2026 FALLOUT

147 vulnerabilities and 3 zero-days made for a brutal April cycle. The month was defined by the final "Enforcement Phase" for RPC hardening, which effectively shuttered legacy print and scan operations worldwide, prompting an emergency OOB response from Microsoft.

DAMAGE RATING

147

VULNERABILITIES

3

ZERO-DAYS EXPLOITED

24

CRITICAL RCES

1

OOB ISSUED

Fallout Timeline

Initial Release — Patch Tuesday Day 0

April 14, 2026 — Microsoft released 147 vulnerabilities. The spotlight hit CVE-2026-28901, a Kernel zero-day bypass allowing full system takeover. Simultaneously, the forced RPC protocol hardening went live, immediately triggering "Access Denied" errors on legacy equipment.

72 Hours Out +3 Days

Legacy Print Blackout: Technical support channels are flooded with reports of older Konica Minolta and HP scanners failing to write to SMB shares due to the RPC enforcement phase.

DCOM Hardening: Admins in the industrial sector report failures in OPC/DCOM communications, breaking automated factory floor monitoring. Registry workarounds are being shared as "stop-gap" measures.

2 Weeks Out Today

OOB Hotpatch: On April 24, Microsoft issued KB5089234 to resolve a critical flaw where the RPC hardening caused valid print requests to hang indefinitely. This is a mandatory "patch for the patch."

Outlook Search Failure: Widespread reports confirm that the April update broke the "Search" functionality in classic Outlook for users with large PST/OST files. Indexing remains stuck at 0% for affected tenants.

Kernel Stability: While CVE-2026-28901 is successfully mitigated, some users report "Page Fault in Non-Paged Area" BSODs on systems running specific third-party antivirus drivers that conflict with the new kernel memory boundaries.