Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2855 articles · 123160 vulns · 36/41 feeds (7d)
← Back to list
4.3
CVE-2026-32202KEVEXPLOITEDPATCHED
Microsoft · Windows 10 Version 1607

Windows Shell Spoofing Vulnerability

Description

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Affected Products

VendorProductVersions
MicrosoftWindows 10 Version 160710.0.14393.0, 10.0.17763.0, 10.0.19044.0, 10.0.19045.0, 10.0.22631.0, 10.0.22631.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0, 6.2.9200.0, 6.2.9200.0, 6.3.9600.0, 6.3.9600.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.25398.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows 11 version 24h2mitre_affected90%
microsoftwindows server 2019 (server core installation)mitre_affected90%
microsoftwindows 11 version 26h1mitre_affected90%
microsoftwindows server 2022, 23h2 edition (server core installation)mitre_affected90%
microsoftwindows 10 version 22h2mitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202(vendor-advisory, patch)

Related News (4 articles)

Tier D
SecurityWeek3h ago
Incomplete Windows Patch Opens Door to Zero-Click Attacks
→ No new info (linked only)
Tier C
Qualys Blog12d ago
Microsoft and Adobe Patch Tuesday, April 2026 Security Update Review
→ No new info (linked only)
Tier C
VulDB12d ago
CVE-2026-32202 | Microsoft Windows up to Server 2025 Shell protection mechanism
→ No new info (linked only)
Tier A
Microsoft MSRC13d ago
CVE-2026-32202 Windows Shell Spoofing Vulnerability
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
10.0.14393.906010.0.17763.864410.0.19044.718410.0.19045.718410.0.22631.693610.0.26100.3269010.0.26200.824610.0.28000.18366.2.9200.260266.3.9600.2313210.0.20348.502010.0.25398.2274
CWECWE-693, CWE-287
PublishedApr 14, 2026
Last enriched2h agov2
Trending Score111🔥
Source articles4
Independent4
Info Completeness10/14
Missing: epss, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-21510EXPKEV
Windows Shell Security Feature Bypass Vulnerability
Trending: 127
HIGHCVE-2026-21513EXPKEV
MSHTML Framework Security Feature Bypass Vulnerability
Trending: 127
HIGHCVE-2026-33825EXPKEV
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 86
MEDIUMCVE-2026-32201EXPKEV
Microsoft SharePoint Server Spoofing Vulnerability
Trending: 74
HIGHCVE-2026-26127EXPKEV
.NET Denial of Service Vulnerability
Trending: 57

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Added to CISA KEV
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Actively Exploited
Apr 24, 2026
Patch Available
Apr 24, 2026
Updated: cweIds
Apr 27, 2026

Version History

v2
Last enriched 2h ago
v2Tier D2h ago

Updated description with details on CVE-2026-32202 and changed severity to HIGH.

cweIds
via SecurityWeek
v112d ago

Initial creation