April 2026 [Double Feature: SQL Another Day + XSS Never Dies]

Episode 30   Published April 14, 2026 8 minute watch

Summary

Two vulnerability classes that should have died years ago, SQL injection and cross-site scripting, both resurface in the April cycle. A SQL injection flaw inside the SQL Server database engine itself lets an attacker who already holds high local privilege escalate to SQL sysadmin, and it ships the same month as a separate SQL Server remote code execution bug, CVE-2026-33120. An actively exploited, unauthenticated cross-site scripting flaw in SharePoint needs no privileges. Roughly 80 Edge and Chromium fixes round out the cycle, with none confirmed exploited.