Cyber Security News[verified]@The_Cyber_NewsActive Exploitation
CVE‑2026‑32202 is a zero‑click Windows Shell vulnerability currently exploited by APT28, with Microsoft confirming active attacks and issuing a Patch Tuesday fix.
blackorbird[verified]@blackorbirdPatch
The post reports that an incomplete patch to CVE‑2026‑21510 gave rise to a new zero‑click vulnerability (CVE‑2026‑32202) that bypasses Microsoft Defender SmartScreen and runs attacker‑controlled code, but it offers no PoC, exploit code, or evidence of active exploitation.
Steven Lim[verified]@0x534cActive Exploitation
A KQL detection query has been released for Windows Shell CVE-2026-32202, with Microsoft confirming it is being actively exploited in the wild.
Steven Lim[verified]@0x534cDisclosure
The snippet provides a basic disclosure and technical description of CVE-2026-32202, without indicating a PoC, exploit, or active exploitation evidence.
780th Military Intelligence Brigade (Cyber)[verified]@780thCPatch
Akamai’s post highlights that the patch for APT28’s zero‑day CVE‑2026‑32202 is incomplete, indicating the vulnerability may still be exploitable.
Welsh ICP Conviction 🏴🏉[verified]@ICPLEGEND1966Active Exploitation
Microsoft confirmed the CVE‑2026‑32202 shell‑spoofing flaw is being actively exploited and that it has already been patched in April 2026, exposing user NTLM hashes. The post underscores the continuous threat and highlights ICP’s role in mitigating infrastructure weaknesses.
SystemCenterDudes[verified]@scdudesPatch
Microsoft has revised its advisory and confirmed a patch for CVE-2026-32202, a spoofing flaw in Windows Shell that could expose sensitive data.
piyokango[verified]@piyokangoActive Exploitation
CISA has added CVE‑2024‑1708 to its KEV catalog, with confirmed active exploitation in the wild and a publicly shared PoC. Vendor patches are available via ConnectWise and Microsoft advisories.