logo

CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks

ID: 1652f2af-3a66-55f9-8439-220a56b9d897

STIX ID: report--1652f2af-3a66-55f9-8439-220a56b9d897

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Abinaya

...
...

On April 28, 2026 CISA added CVE-2026-32202—a critical zero-day in the Microsoft Windows Shell that enables network spoofing and active in-the-wild exploitation—to its Known Exploited Vulnerabilities catalog, issuing a binding May 12, 2026 remediation deadline for federal agencies and urging all organizations to immediately apply vendor mitigations, patch affected systems, and monitor for spoofing attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.