CVE-2026-32202Active Exploitation(microsoft / windows_10_1607)

CRITICALCVSS 4.3 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 51 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

9.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-693

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 147 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 213 mentions across 37 observed days

What's happening

  • Active exploitation reported across 147 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 12 signals
  • Patch or workaround mentioned in 93 signals
  • Technical details provided in 109 signals
  • General: 26 classified signals
  • Peaked 32d ago at 51 mentions (2026-04-28); latest day: 1
  • 213 total mentions across 37 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline213 mentions / 37d
013263851Mentions · 2026-04-14: 1Mentions · 2026-04-17: 1Mentions · 2026-04-24: 1Mentions · 2026-04-27: 4Mentions · 2026-04-28: 51Mentions · 2026-04-29: 40Mentions · 2026-04-30: 27Mentions · 2026-05-01: 14Mentions · 2026-05-02: 1Mentions · 2026-05-03: 4Mentions · 2026-05-04: 6Mentions · 2026-05-05: 1Mentions · 2026-05-06: 4Mentions · 2026-05-07: 4Mentions · 2026-05-09: 3Mentions · 2026-05-11: 1Mentions · 2026-05-12: 3Mentions · 2026-05-13: 3Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1Mentions · 2026-05-20: 1Mentions · 2026-05-25: 6Mentions · 2026-05-26: 2Mentions · 2026-05-27: 5Mentions · 2026-05-30: 6Mentions · 2026-06-04: 2Mentions · 2026-06-05: 1Mentions · 2026-06-12: 1Mentions · 2026-06-13: 3Mentions · 2026-06-15: 8Mentions · 2026-06-25: 1Mentions · 2026-07-14: 1Mentions · 2026-07-29: 1Mentions · 2026-08-02: 1Mentions · 2026-08-05: 1Mentions · 2026-09-08: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-28: 3PoC Mentioned / Linked · 2026-04-29: 2PoC Mentioned / Linked · 2026-04-30: 2PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-09-08: 1Exploit Tool / Code · 2026-05-06: 1Exploit Tool / Code · 2026-05-12: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-05-27: 1Exploit Tool / Code · 2026-07-14: 1Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-04-28: 43Active Exploitation · 2026-04-29: 36Active Exploitation · 2026-04-30: 18Active Exploitation · 2026-05-01: 10Active Exploitation · 2026-05-02: 1Active Exploitation · 2026-05-03: 2Active Exploitation · 2026-05-04: 6Active Exploitation · 2026-05-06: 3Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-09: 2Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-05-12: 2Active Exploitation · 2026-05-13: 3Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-16: 1Active Exploitation · 2026-05-25: 2Active Exploitation · 2026-05-26: 1Active Exploitation · 2026-05-27: 3Active Exploitation · 2026-05-30: 2Active Exploitation · 2026-06-04: 1Active Exploitation · 2026-06-05: 1Active Exploitation · 2026-06-15: 4Active Exploitation · 2026-07-29: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-27: 4Patch / Workaround · 2026-04-28: 25Patch / Workaround · 2026-04-29: 11Patch / Workaround · 2026-04-30: 13Patch / Workaround · 2026-05-01: 8Patch / Workaround · 2026-05-03: 2Patch / Workaround · 2026-05-04: 4Patch / Workaround · 2026-05-06: 2Patch / Workaround · 2026-05-07: 3Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 2Patch / Workaround · 2026-05-25: 3Patch / Workaround · 2026-05-26: 2Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-30: 2Patch / Workaround · 2026-06-04: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-15: 3Patch / Workaround · 2026-07-14: 1Patch / Workaround · 2026-07-29: 1Patch / Workaround · 2026-09-08: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-27: 4Technical Details · 2026-04-28: 19Technical Details · 2026-04-29: 21Technical Details · 2026-04-30: 13Technical Details · 2026-05-01: 7Technical Details · 2026-05-03: 3Technical Details · 2026-05-04: 3Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 2Technical Details · 2026-05-09: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 3Technical Details · 2026-05-25: 4Technical Details · 2026-05-26: 2Technical Details · 2026-05-27: 3Technical Details · 2026-05-30: 3Technical Details · 2026-06-12: 1Technical Details · 2026-06-13: 3Technical Details · 2026-06-15: 5Technical Details · 2026-07-14: 1Technical Details · 2026-08-02: 1Technical Details · 2026-09-08: 104-1404-2704-3005-0305-0605-1105-1405-2005-2706-0506-1507-2909-08
Signal classification6 categories
Active Exploitation
13864.8%
General
2612.2%
Patch
2310.8%
Disclosure
209.4%
Exploit
52.3%
Discloir
10.5%
Referenced assets108 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-141
General1
2026-04-171
Disclosure1
2026-04-241
Patch1
2026-04-274
Discloir1Exploit1Patch2
2026-04-2851
Active Exploitation42Disclosure3General2Patch4
2026-04-2940
Active Exploitation35Disclosure4Patch1
2026-04-3027
Active Exploitation18Disclosure3General2Patch4
2026-05-0114
Active Exploitation9General2Patch3
2026-05-021
Active Exploitation1
2026-05-034
Active Exploitation2Disclosure1General1
2026-05-046
Active Exploitation6
2026-05-051
General1
2026-05-064
Active Exploitation2Exploit1General1
2026-05-074
Active Exploitation1Disclosure1Patch2
2026-05-093
Active Exploitation2Disclosure1
2026-05-111
Active Exploitation1
2026-05-123
Active Exploitation2General1
2026-05-133
Active Exploitation3
2026-05-141
Active Exploitation1
2026-05-151
General1
2026-05-161
Active Exploitation1
2026-05-201
General1
2026-05-256
Active Exploitation2Exploit1General2Patch1
2026-05-262
Active Exploitation1Patch1
2026-05-275
Active Exploitation2Exploit1General2
2026-05-306
Active Exploitation1General3Patch2
2026-06-042
Active Exploitation1Disclosure1
2026-06-051
Active Exploitation1
2026-06-121
Patch1
2026-06-133
Disclosure1General2
2026-06-158
Active Exploitation4Disclosure2General2
2026-06-251
General1
2026-07-141
Disclosure1
2026-07-291
Patch1
2026-08-021
Disclosure1
2026-08-051
General1
2026-09-081
Exploit1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 WARNING: Microsoft confirmed active exploitation of a Windows flaw → CVE-2026-32202. The bug stems from an incomplete fix, allowing attackers to steal credentials via SMB authentication when a malicious file is opened. 🔗 Read details → https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html

    Post summary

    Microsoft reports that CVE-2026-32202 is actively exploited to steal SMB credentials through malicious files, but no PoC or patch information is provided.

    11124732211135.8K
    1.8M followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 New Windows 0-Click Vulnerability Exploited to Bypass Defender SmartScreen Source: https://cybersecuritynews.com/windows-shell-security-0-click-vulnerability/ A critical zero-click authentication coercion vulnerability, tracked as CVE-2026-32202, stemming from an incomplete patch for a Windows Shell security feature bypass actively weaponized by the Russian APT28 threat group. Microsoft confirmed active exploitation of the flaw and released a fix as part of its April 2026 Patch Tuesday update. The attack's primary mechanism abuses the Windows Shell namespace parsing pipeline. APT28 embedded a malicious LinkTargetIDList structure inside the LNK file, a binary IDList that Windows Explorer parses and renders, similar to how Control Panel items are displayed. #cybersecuritynews #vulnerability #microsoft

    Post summary

    CVE‑2026‑32202 is a zero‑click Windows Shell vulnerability currently exploited by APT28, with Microsoft confirming active attacks and issuing a Patch Tuesday fix.

    57612658517.9K
    67.1K followersView on X
  • blackorbird@blackorbird
    Patch

    The second vulnerability (CVE-2026-21510) bypasses security features such as the Microsoft Defender SmartScreen and executes attacker-controlled code, which is stored on the attacker's remote server. An incomplete patch for CVE-2026-21510 (an #APT28 exploit) created a new zero-click vulnerability: CVE-2026-32202. https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202

    Post summary

    The post reports that an incomplete patch to CVE‑2026‑21510 gave rise to a new zero‑click vulnerability (CVE‑2026‑32202) that bypasses Microsoft Defender SmartScreen and runs attacker‑controlled code, but it offers no PoC, exploit code, or evidence of active exploitation.

    151017010320.4K
    42.7K followersView on X
  • Gray Hats@the_yellow_fall
    Discloir

    Akamai reveals CVE-2026-32202: A zero-click Windows Shell flaw allowing Fancy Bear to steal NTLM hashes. Discover why the original patch was not enough. #CVE202632202 #FancyBear #WindowsSecurity #CyberSecurity #Akamai #ZeroClick #NTLM #InfoSec #APT28 https://meterpreter.org/the-zero-click-ghost-how-an-incomplete-patch-left-windows-open-to-fancy-bears-credential-theft/ https://t.co/Ofv9fQmXNv

    Post summary

    Akamai announced CVE-2026-32202, a zero-click Windows Shell flaw that permits Fancy Bear to steal NTLM hashes, noting that the original patch was insufficient.

    114057313.9K
    12.5K followersView on X
  • Steven Lim@0x534c
    Active Exploitation

    🔍Monitoring Exploitation of Windows Shell CVE-2026-32202 https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html Crafted a KQL query to monitor exploitation attempts of Windows Shell CVE-2026-32202. Detection engineering isn’t just about writing rules—it’s about mapping real-world pivots across vulnerabilities, credentials, and network behaviors. 🎯 KQL Code: https://github.com/SlimKQL/Detections.AI/blob/main/KQL/monitoring-exploitation-of-windows-shell-cve-2026-32202.kql #Cybersecurity #DefenderXDR #WindowsShellVulnerability

    Post summary

    A KQL detection query has been released for Windows Shell CVE-2026-32202, with Microsoft confirming it is being actively exploited in the wild.

    29051263.6K
    7.2K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added ConnectWise ScreenConnect path traversal vulnerability CVE-2024-1708 & Microsoft Windows protection mechanism failure vulnerability CVE-2026-32202 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity https://t.co/dQcNvxcejN

    Post summary

    The tweet announces that CVE‑2024‑1708 and CVE‑2026‑32202 are now listed in the DHS Known Exploited Vulnerabilities Catalog, confirming they are actively exploited. No PoC, exploit code, or patch details are provided.

    41704397.6K
    299.5K followersView on X
  • Steven Lim@0x534c
    Disclosure

    Vulnerability Profile: CVE-2026-32202 - Windows Shell July 31, 2026 update: Updated to reflect recent patches and additional affected versions.😅 CVE-2026-32202 is an important severity protection mechanism failure vulnerability in Windows Shell that could allow an unauthorized attacker to perform spoofing over a network. An attacker would need to send a victim a malicious file and trick them into executing the file for this vulnerability to be successfully exploited. An attacker who successfully exploits this vulnerability could view some sensitive information, but not all resources within the impacted component might be divulged to the attacker. CVE-2026-32202 - Windows Shell Detection https://detections.ai/share/rule/hZHH9dSg #Cybersecurity #WindowsShell #Vulnerability

    Post summary

    The snippet provides a basic disclosure and technical description of CVE-2026-32202, without indicating a PoC, exploit, or active exploitation evidence.

    19036183.7K
    7.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Akamai uncovers CVE-2026-32202: A zero-click LNK flaw used by APT28 to steal Windows NTLM hashes silently. No user interaction required. Patch alert! #ZeroClick #APT28 #FancyBear #CyberSecurity #InfoSec #WindowsSecurity #NTLM #Akamai https://securityonline.info/cve-2026-32202-zero-click-lnk-vulnerability-fancy-bear/ https://t.co/zwqkwrOzfy

    Post summary

    Akamai reports CVE-2026-32202 as a zero-click LNK flaw exploited by APT28 to silently harvest NTLM hashes; a patch is announced and should be applied immediately.

    19029161.5K
    12.5K followersView on X
  • 0patch@0patch
    Patch

    Broken official patches for Windows Shell Spoofing Vulnerability (CVE-2026-32202) https://0patch.com/blog/micropatches-released-for-windows-shell-spoofing-vulnerability-cve-2026-32202 https://t.co/xZU8zKMI3l

    Post summary

    The post reports that official Windows patches for CVE‑2026‑32202 are ineffective and that new micro‑patches have been released, but does not provide exploit code or active attack evidence.

    1701851.6K
    8.4K followersView on X
  • 780th Military Intelligence Brigade (Cyber)@780thC
    Patch

    A Shortcut to Coercion: Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202 Akamai https://www.akamai.com/blog/security-research/incomplete-patch-apt28s-zero-day-cve-2026-32202 @Akamai

    Post summary

    Akamai’s post highlights that the patch for APT28’s zero‑day CVE‑2026‑32202 is incomplete, indicating the vulnerability may still be exploitable.

    1301321.1K
    35.3K followersView on X
  • Welsh ICP Conviction 🏴󠁧󠁢󠁷󠁬󠁳󠁿🏉@ICPLEGEND1966
    Active Exploitation

    🚨 MICROSOFT WINDOWS ZERO-CLICK CREDENTIAL THEFT SHOWS WHY THE INTERNET NEEDS $ICP ♾️ BY @DFINITY Microsoft has confirmed active exploitation of CVE-2026-32202, a Windows Shell spoofing flaw patched in April 2026. The issue matters because it reportedly allowed a malicious Windows shortcut / LNK path to trigger an automatic SMB authentication attempt, exposing a victim’s Net-NTLMv2 hash for possible relay or offline cracking. Akamai linked the wider exploit chain to APT28 / Fancy Bear activity targeting Ukraine and EU nations. CISA has also added the Windows flaw to its Known Exploited Vulnerabilities catalogue. This is the brutal reality of today’s internet stack: Centralized operating systems. Patch gaps. Credential leakage. Remote authentication abuse. Nation-state exploit chains. Users and enterprises forced to trust layers they cannot verify. That is exactly why $ICP ♾️ by @DFINITY matters. ICP is not just another blockchain moving tokens around. It is a full-stack onchain cloud where applications can run from canisters, serve web frontends, store state, execute logic, and verify computation directly onchain. No traditional web server required. No exposed centralized backend by default. No hidden database layer sitting behind a fragile login wall. No “trust us, it’s patched” infrastructure model. To be clear: ICP does not magically patch Windows endpoints or stop every user-device exploit. But it does attack a deeper infrastructure problem: the internet’s dependency on centralized, opaque, compromise-prone backend systems. The future needs infrastructure where software, data, identity, and compute are cryptographically verifiable by design. That is the $ICP thesis. While legacy systems keep fighting zero-days, patch gaps, credential theft, and state-backed exploit chains, ICP is building toward a tamper-resistant, sovereign, onchain cloud for the next internet. $ICP by @DFINITY is not hype. It is infrastructure. It is security architecture. It is the World Computer. If you value this content and want to support more $ICP research, posts, and education, ICP contributions are welcome: ICP Donation Address: 1e672d038cebc619d93186418fa98f6499dbdb9cfdfac54f366c61a4a4ee4362 #ICP #InternetComputer #DFINITY #WorldComputer #OnchainCloud #CyberSecurity #ZeroDay #APT28 #CloudSecurity #DecentralizedCloud #Canisters #Web3 #Blockchain #AI #SovereignCloud #VerifiableCompute

    Post summary

    Microsoft confirmed the CVE‑2026‑32202 shell‑spoofing flaw is being actively exploited and that it has already been patched in April 2026, exposing user NTLM hashes. The post underscores the continuous threat and highlights ICP’s role in mitigating infrastructure weaknesses.

    040121228
    1.5K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Active Exploitation

    ⚠️ Microsoft confirme l'exploitation de la CVE-2026-32202 Une faille de sécurité présente dans l'interface Windows Shell est considérée comme exploitée par Microsoft. Ma publication à ce sujet : - https://www.it-connect.fr/vols-didentifiants-sur-windows-microsoft-revele-lexploitation-de-la-cve-2026-32202/ #windows #infosec #cybersecurite https://t.co/HA4x6jr5tB

    Post summary

    The tweet indicates Microsoft confirms CVE-2026-32202 is actively exploited via the Windows Shell interface, with no PoC, exploit code, patch, or detailed technical description provided.

    03093663
    11.5K followersView on X
  • SystemCenterDudes@scdudes
    Patch

    FYI - Microsoft has revised its advisory for a now-patched, high-severity #security flaw impacting Windows Shell. The vulnerability is CVE-2026-32202, a spoofing vulnerability that could allow an attacker to access sensitive information. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202 #MSIntune https://t.co/RqHcueMk7J

    Post summary

    Microsoft has revised its advisory and confirmed a patch for CVE-2026-32202, a spoofing flaw in Windows Shell that could expose sensitive data.

    0101041.3K
    9.9K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/28追加) 🛡️No.1585 CVE-2024-1708 ConnectWise ScreenConnect Path Traversal Vulnerability ==================================== ✅概要 ・深刻度:重要 8.4 (CVSS Base) / Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H ConnectWise ScreenConnect 23.9.7 以前に存在するパス・トラバーサルの脆弱性。特権を持つ攻撃者により、リモートコードの実行や機密データ・重要システムへ直接影響を与える恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・self-hosted / on-premise の ConnectWise ScreenConnect 23.9.7 以前が稼働していること。 ・攻撃者が管理者権限を有し、Extensions 機能を利用できること。 ・細工された ZIP 形式の拡張ファイルをアップロードできること。 ✅悪用時影響 ・制限されたディレクトリ外へファイルを書き込まれる ・App_Extensions 配下の想定外の場所へ ASPX / ASHX などのファイルを配置され、リモートからコード実行 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Huntress は公開直後に active exploitation in the wild を確認したとし、Microsoft も Storm-1175 が CVE-2024-1709 と CVE-2024-1708 を悪用対象に含めていたと報告 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-1708 https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 🛡️No.1586 CVE-2026-32202 Microsoft Windows Protection Mechanism Failure Vulnerability ==================================== ✅概要 ・深刻度:注意 4.3 (CVSS Base) / Microsoft Corporation ・種別:保護メカニズムの不具合 (CWE-693) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N Windows Shell における保護機構の不備により、事前認証されていない攻撃者がネットワーク経由でスプーフィングを実行する恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Windows 10、Windows 11、Windows Server のバージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要、かつ利用者の関与が必要。 ✅悪用時影響 ・ネットワーク経由でスプーフィングを実行される ・利用者を欺いて機微情報へアクセスされる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Microsoft は本脆弱性が実際に悪用されていると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-32202 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202 https://www.cisa.gov/news-events/alerts/2026/04/28/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has added CVE‑2024‑1708 to its KEV catalog, with confirmed active exploitation in the wild and a publicly shared PoC. Vendor patches are available via ConnectWise and Microsoft advisories.

    0001135.0K
    43.6K followersView on X
  • 阿绎 AYi@AYi_AInotes
    Active Exploitation

    Theo 这张清单刷屏了,近期的安全事件如下: CopyFail(Linux 系统被破解) CopyFail 2/Dirty Frag(Linux 内核脏碎片漏洞) Next.js 框架出现 13 个安全警告 MacOS 26.5 系统修复了 70 多个通用漏洞披露(CVE)漏洞 iOS 26.5 系统修复了约 50 个通用漏洞披露(CVE)漏洞 YellowKey(Windows Bitlocker 全盘加密被破解) GreenPlasma(Windows 权限提升漏洞) CVE-2026-21510 和 CVE-2026-21513 被证实由俄罗斯用于 Windows 远程代码执行漏洞攻击 CVE-2026-32202 被单独证实由俄罗斯用于获取敏感文档 Mini-Shai Hulud(超过 300 个 JS 和 Python 软件包因 GitHub Action 缓存投毒而被入侵) 谷歌证实,他们发现了利用人工智能对某个未知的 “开源、基于 Web 的系统管理工具” 进行零日漏洞攻击的情况 Canvas(大多数学校使用的流行学习管理系统)被完全破解 PAN-OS( Palo Alto Networks 公司的操作系统)因严重等级为 9.3 的 CVE-2026-0300 漏洞被破解 我连着看了三天相关报告,越看越觉得这不是个危言耸听的恐怖故事, 更像是软件工程进入后AI安全时代的入学通知。 最关键的信号藏在 CopyFail 里: 一个 732 字节的 Python 脚本, 确定性拿下 2017 年后几乎所有 Linux 发行版的 root。 这玩意竟然是 AI 辅助发现的。 Google 也在同一周确认,AI 驱动的零日已经在野利用了, 俄罗斯 APT 直接武器化两个 Windows CVE, Mini-Shai Hulud 一次劫持 300+ 个 JS/Python 包。 以前一个漏洞躺三年才被人发现, 现在 AI 扫描+AI 利用,未知→已知→武器化几乎同步发生。 更狠的是供应链, Mini-Shai Hulud 告诉所有人一件事: 你信任的 CI/CD 才是最大的后门。 你以为用官方 GitHub Action 就安全, 其实是把 OIDC token 的钥匙拱手送给攻击者。 Perry Metzger 说过一句我反复琢磨的话: bug 的总量是有限的,AI 正在快速耗尽低挂果实。 也就是说,以前安全是"被动 patch", 现在开始转向"AI 实时免疫"。 未来不再是人盯人,会变成 AI 盯 AI。 所以 Theo 问 Are you scared yet, 我的答案是不怕,但必须立刻行动。 第一步不是全站 patch,是把供应链审计提到 P0, GH Actions 全审一遍,禁用 pull_request_target, 强制 SLSA Level 3,启用 SBOM。 那些把"安全作为第一原则"写进 DNA 的团队, 接下来 3-5 年会活得最舒服, 其他人要交的学费,可能比想象中贵得多~

    Post summary

    The post enumerates several CVEs with confirmed active exploitation, provides PoC and exploit code, highlights vendor patches, and stresses the urgency of supply‑chain security, underscoring the rapid AI‑driven weaponization of vulnerabilities.

    700331.1K
    44.0K followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202 http://dlvr.it/TSt5hK #CVE2026 #MicrosoftSecurity #WindowsShell #CyberSecurity #InfoSec https://t.co/ULccuzKALY

    Post summary

    Microsoft confirms that CVE-2026-32202 in Windows Shell is actively exploited in the wild; the tweet provides no PoC or technical details, nor does it mention a patch or workaround.

    03062547
    56.7K followersView on X
  • Intel IQ@intliq_ai
    Active Exploitation

    1/7 🚨 Microsoft Under Attack: Active Exploitation of Windows Shell CVE-2026-32202 Has Been Confirmed According to @TheHackersNews, @Microsoft has confirmed that a recently patched Windows Shell vulnerability, CVE-2026-32202, is now being exploited in real-world attacks. https://t.co/xgFxpOFKHG

    Post summary

    CVE-2026-32202, a Windows Shell vulnerability, was recently patched but is now actively being exploited in real-world attacks as confirmed by Microsoft.

    110619.6K
    10 followersView on X
  • Secure.com@Securedotcom
    Patch

    @TheHackersNews An incomplete fix is almost worse than no fix. Organizations patched the original, marked it closed, moved on. CVE-2026-32202 means that checkbox didn't actually mean what anyone thought it did.

    Post summary

    The post notes that an incomplete fix for CVE‑2026‑32202 was applied but not fully effective, with no proof of concept, exploit, or active attacks reported.

    010712.0K
    79 followersView on X
  • dbugs@ptdbugs
    Exploit

    Exploit for CVE-2026-32202 in Windows Explorer for Sale Read on dbugs: https://dbu.gs/news/exploit-for-cve-2026-32202-in-windows-explorer-for-sale-20260908 Vulnerability Type: Information Disclosure via NTLM Authentication Coercion Vulnerable Versions: Windows 10/11/Windows Server 2012 and later without the April 2026 patch Price: $6,500 The author is selling an exploit for the CVE-2026-32202 (https://dbu.gs/vulnerability/PT-2026-32854?fts%5Bvalue%5D=CVE-2026-32202) vulnerability. It is advertised as a zero-click exploit via a Windows Explorer vulnerability related to the processing of specially crafted LNK files: The user simply needs to open a folder containing a malicious shortcut; when Explorer attempts to display its icon or metadata, it automatically processes the embedded Control Panel object and may initiate an SMB connection to the attacker’s server, transmitting NTLM authentication credentials. In this case, clicking on the file itself is not required, and SmartScreen does not trigger, since the network call occurs at an earlier stage of the shortcut’s processing, even before it is actually launched. It is worth noting that publicly available exploits exist for this vulnerability. CVE-2026-32202 — PT-2026-32854: https://dbu.gs/vulnerability/PT-2026-32854

    Post summary

    The message markets a zero‑click Windows Explorer exploit for CVE‑2026‑32202, explaining how malicious LNK files can coerce NTLM credentials, but does not report active attacks or provide a patch.

    01043846
    3.6K followersView on X
  • The Cyber Crooners@cybercrooners
    Active Exploitation

    Microsoft confirmed active exploitation of a Windows flaw (CVE-2026-32202). Open the wrong file → attackers steal your credentials via SMB authentication. The bug came from an incomplete patch. Update your Windows NOW. @thecybercrooners #CyberSecurity #Microsoft #InfoSec https://t.co/z1LIrFmrk6

    Post summary

    Microsoft confirmed active exploitation of CVE‑2026‑32202, warning that merely opening a wrong file can lead to credential theft via SMB authentication; users are urged to patch Windows immediately.

    03050217
    271 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more