logo

Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

ID: 9ba63797-d149-59e9-85fc-190e63083d94

STIX ID: report--9ba63797-d149-59e9-85fc-190e63083d94

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: [email protected] (The Hacker News)

...
...

Microsoft revised its advisory to confirm active exploitation of CVE-2026-32202, a Windows Shell spoofing/authentication coercion flaw tied to an incomplete patch for CVE-2026-21510; Akamai researchers attribute exploitation to APT28 using malicious LNK files and UNC-based CPL loading to force SMB/NTLM authentication and steal credential hashes, with attacks observed against targets in Ukraine and EU and fixes issued across February–April 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.