CISA, Microsoft warn of active exploitation of Windows Shell vulnerability (CVE-2026-32202)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21510 +1 in the same advisory: …21513 | Security Feature Bypass in Microsoft Windows Shell Actively Exploited (CVE-2026-21510) Microsoft Windows Shell contains a protection mechanism failure (CWE-693) that allows an unauthorized attacker to bypass a security feature, which CISA notes can be reached over a network. Successful exploitation defeats a Windows defense-in-depth control, weakening protections an attacker would otherwise have to evade as part of a broader intrusion; the available data does not describe a code-execution or privilege-escalation gain. Any system running Microsoft Windows falls within CISA's published affected scope, and specific version ranges have not been enumerated in the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-10, confirming exploitation in the wild, and its EPSS score of 26.2% (98th percentile) signals elevated near-term exploitation risk; ransomware use is unknown and no public proof-of-concept is known. Do: Apply Microsoft's applicable Windows security update through Windows Update/WSUS or your patch-management process as soon as practical, prioritizing internet-exposed and high-value systems; because the issue is in CISA's KEV catalog (added 2026-02-10), U.S. federal agencies must apply the vendor fix, applicable BOD 22-01 mitigations (including for cloud services), or discontinue use by the catalog due date. Until patched, follow Microsoft's mitigation guidance from vendor advisories and monitor for updates, since specific affected builds and the exploited security feature have not been detailed in the available data. | 8.8 | 26% | KEV |
| mass≈1+ billion Windows devices | |
| CVE-2026-32202 | Spoofing Flaw in Windows Shell (CVE-2026-32202) Actively Exploited A protection mechanism in the Windows Shell fails (CWE-693), allowing an unauthorized attacker to perform spoofing against the shell over a network. Per the CVSS vector, the attack is network-based, requires no privileges or special conditions, but does require the targeted user to interact with attacker-supplied content. The impact is limited to confidentiality: an attacker can misrepresent information presented through the Windows Shell, gaining a spoofing foothold rather than code execution, privilege escalation, or persistence. Any organization running the affected Windows 10, Windows 11, or Windows Server builds is exposed, which effectively means most Windows estates. Microsoft has confirmed active exploitation, CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-04-28, and a fix shipped in Microsoft's April 2026 Patch Tuesday release. Do: Apply Microsoft's April 2026 security updates to all affected Windows 10, Windows 11, and Windows Server hosts as a priority; the flaw is on CISA's KEV catalog, so U.S. federal agencies must patch within BOD 22-01 timelines or apply vendor-recommended mitigations. Until patched, note that exploitation requires user interaction with spoofed shell content, so user awareness about verifying shell-rendered information is a partial mitigations. No public PoC is known, but confirmed in-the-wild exploitation warrants prioritizing user-facing and internet-reachable systems for patching. | 4.3 | 64% | KEV |
| mass~1 billion+ Windows devices (affected builds span all supported Windows 10 and Windows 11 desktops plus Windows Server 2012-2022) |
Full article333 words · extracted from helpnetsecurity.com · click to collapse
Attackers are exploiting CVE-2026-32202, a zero-click Windows Shell spoofing vulnerability that causes victims’ systems to authenticate the attacker’s server, CISA and Microsoft have warned.
About CVE-2026-32202
CVE-2026-32202 stems from an incomplete patch for CVE-2026-21510, a vulnerability that, in conjunction with CVE-2026-21513, has been exploited by APT28 (aka Fancy Bear) via weaponized LNK files that bypass Windows security features.
Microsoft fixed those two flaws in February 2026, successfully preventing the initial remote code execution and SmartScreen bypass.
But, according to Dahan, the fix did not prevent the victim machine from reaching out to the attacker’s server, even if the victim refrained from opening the malicious LNK (Windows shortcut) file.
The initiation of an SMB connection to the attacker’s server happens when the user opens the folder where the LNK file was downloaded (i.e., when Windows Explorer renders its contents and tries to fetch an icon for the shortcut).
“This server message block (SMB) connection triggers an automatic NTLM authentication handshake, sending the victim’s Net-NTLMv2 hash to the attacker, which can later be used for NTLM relay attacks and offline cracking,” Dahan explained.
CVE-2026-32202 affects a range of supported Windows 10, 11, and Windows Server versions.
Incomplete fixes, incomplete picture
Akamai’s discovery highlights the risky gap between a patch being issued and systems being genuinely protected.
That risk is compounded when vendors fail to flag a vulnerability as actively exploited at the time of patching, which is precisely what happened here: Microsoft pushed out a fix for CVE-2026-32202 on April 14, 2026, without marking it as exploited, meaning security teams had no formal signal to treat it with urgency.
CISA’s and Microsoft’s confirmation of active exploitation came more than two weeks later.
Organizations should apply Microsoft’s April 14 patch (if they haven’t already). Where feasible, blocking outbound SMB traffic at the network perimeter will also limit exposure to NTLM coercion attacks.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/04/29/windows-cve-2026-32202-exploited/