CVE-2026-32202

Microsoft Windows — Microsoft Windows Protection Mechanism Failure Vulnerability

Severity
critical
Actively exploited
actively exploited (KEV)
99.1 %
Critical — model predicts very high exploitation likelihood in the next 30 days.
Published
2026-04-28 00:00 UTC
CWE-693

Weakness classes (CWE)

  • CWE-693Pillar

    Protection Mechanism Failure

    The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

    cwe.mitre.org →

Description

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Source: CISA_KEV

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Linked advisories