logo

CISA orders feds to patch Windows flaw exploited as zero-day

ID: c406713a-3d2b-5cb4-9676-01f7569ee804

STIX ID: report--c406713a-3d2b-5cb4-9676-01f7569ee804

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Sergiu Gatlan

...
...

CISA has ordered U.S. federal agencies to urgently patch a Windows zero-day (CVE-2026-32202) — described as a zero-click credential-theft vector left after an incomplete fix for CVE-2026-21510 — following active exploitation reports; Akamai and CERT-UA tied exploitation activity to APT28 and urged immediate mitigation, and CISA added the flaw to its Known Exploited Vulnerabilities catalog with a May 12 remediation deadline under BOD 22-01.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.