cbcvebase.
CVE-2026-32202
published 2026-04-14

CVE-2026-32202: Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

PriorityP276medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-05-12
Exploited in the wild
EPSS
64.09%
99.1th percentile
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1607< 10.0.14393.906010.0.14393.9060
microsoftwindows_10_1809< 10.0.17763.864410.0.17763.8644
microsoftwindows_10_21h2< 10.0.19044.718410.0.19044.7184
microsoftwindows_10_22h2< 10.0.19045.718410.0.19045.7184
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.906010.0.14393.9060
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.864410.0.17763.8644
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.718410.0.19044.7184
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.718410.0.19045.7184
microsoftwindows_11_23h2< 10.0.22631.693610.0.22631.6936
microsoftwindows_11_24h2< 10.0.26100.824610.0.26100.8246
microsoftwindows_11_25h2< 10.0.26200.824610.0.26200.8246
microsoftwindows_11_26h1< 10.0.28000.183610.0.28000.1836
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.693610.0.22631.6936
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.693610.0.22631.6936
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.824610.0.26100.8246
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.824610.0.26200.8246
microsoftwindows_11_version_26h1>= 10.0.28000.0 < 10.0.28000.183610.0.28000.1836
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.260266.2.9200.26026
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.231326.3.9600.23132
microsoftwindows_server_2016< 10.0.14393.906010.0.14393.9060
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.906010.0.14393.9060
microsoftwindows_server_2019< 10.0.17763.864410.0.17763.8644
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.864410.0.17763.8644
microsoftwindows_server_2022< 10.0.20348.502010.0.20348.5020

Detection & IOCsextracted from sources · hover to see the quote

filenameexploit.lnk
port445
  • Monitor for Net-NTLMv2 hash capture events on SMB — the vulnerability enables zero-click credential theft via auto-parsed LNK files, usable for NTLM relay attacks and offline cracking.
  • Alert on SMB connections initiated from Windows Shell/File Explorer process (explorer.exe) to non-local UNC paths, particularly when triggered without explicit user file execution.
  • Correlate CVE-2026-32202 exploitation attempts with prior CVE-2026-21510 and CVE-2026-21513 activity — APT28 chained all three in campaigns targeting Ukraine and EU nations starting December 2025.
  • ·The February 2026 patch for CVE-2026-21510 only partially mitigated the attack chain — it added a SmartScreen check on CPL digital signature/origin zone but did NOT block the UNC path resolution and SMB connection, leaving the NTLM hash leak vector (CVE-2026-32202) open until the April 2026 Patch Tuesday fix.
  • ·CVE-2026-32202 is an incomplete patch bypass of CVE-2026-21510 — defenders who applied the February 2026 patch but not the April 2026 Patch Tuesday update (KB2026-04214) remain vulnerable to NTLM hash capture.

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
vulncheck4.3MEDIUM
cisa4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.