Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
ID: 9ba63797-d149-59e9-85fc-190e63083d94
STIX ID: report--9ba63797-d149-59e9-85fc-190e63083d94
Feed Name: The Hacker News
Threat Score
Microsoft revised its advisory to confirm active exploitation of CVE-2026-32202, a Windows Shell spoofing/authentication coercion flaw tied to an incomplete patch for CVE-2026-21510; Akamai researchers attribute exploitation to APT28 using malicious LNK files and UNC-based CPL loading to force SMB/NTLM authentication and steal credential hashes, with attacks observed against targets in Ukraine and EU and fixes issued across February–April 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
