Critical Zero-Click Vulnerability in Windows Shell Exploited by APT28
ID: 49ae4ed6-9b78-53bd-b439-421963ffef02
STIX ID: report--49ae4ed6-9b78-53bd-b439-421963ffef02
Feed Name: ThreatCluster
Threat Score
**Critical zero-click Windows Shell vulnerability (CVE-2026-32202) exploited by APT28 — patch immediately.** Microsoft confirmed that a critical zero-click authentication coercion flaw in Windows Shell is being actively exploited by the Russian APT28 group; a fix was released on April 14, 2026 as part of Patch Tuesday and organizations should apply it promptly to mitigate widespread risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
