CVE-2026-32202

Confirmed PUBLISHED

Windows Shell Spoofing Vulnerability

Microsoft · Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)

1 day faster than CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
4.3 Medium EPSS 64.1%

At a Glance

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

cisa windows microsoft
CVE Published
Apr 14, 2026
Exploitation Reported
Jun 01, 2026
CVSS
4.3 Medium
EPSS
64.1%
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
Microsoft
Windows 10 Version 1607

10.0.14393.0 to < 10.0.14393.9060

Affected
Microsoft
Windows 10 Version 1809

10.0.17763.0 to < 10.0.17763.8644

Affected
Microsoft
Windows 10 Version 21H2

10.0.19044.0 to < 10.0.19044.7184

Affected
Microsoft
Windows 10 Version 22H2

10.0.19045.0 to < 10.0.19045.7184

Affected
Microsoft
Windows 11 version 22H3

10.0.22631.0 to < 10.0.22631.6936

Affected
Microsoft
Windows 11 Version 23H2

10.0.22631.0 to < 10.0.22631.6936

Affected
Microsoft
Windows 11 Version 24H2

10.0.26100.0 to < 10.0.26100.8246

Affected
Microsoft
Windows 11 Version 25H2

10.0.26200.0 to < 10.0.26200.8246

Affected
Microsoft
Windows 11 version 26H1

10.0.28000.0 to < 10.0.28000.1836

Affected
Microsoft
Windows Server 2012

6.2.9200.0 to < 6.2.9200.26026

Affected
Microsoft
Windows Server 2012 (Server Core installation)

6.2.9200.0 to < 6.2.9200.26026

Affected
Microsoft
Windows Server 2012 R2

6.3.9600.0 to < 6.3.9600.23132

Affected
Microsoft
Windows Server 2012 R2 (Server Core installation)

6.3.9600.0 to < 6.3.9600.23132

Affected
Microsoft
Windows Server 2016

10.0.14393.0 to < 10.0.14393.9060

Affected
Microsoft
Windows Server 2016 (Server Core installation)

10.0.14393.0 to < 10.0.14393.9060

Affected
Microsoft
Windows Server 2019

10.0.17763.0 to < 10.0.17763.8644

Affected
Microsoft
Windows Server 2019 (Server Core installation)

10.0.17763.0 to < 10.0.17763.8644

Affected
Microsoft
Windows Server 2022

10.0.20348.0 to < 10.0.20348.5020

Affected
Microsoft
Windows Server 2022, 23H2 Edition (Server Core installation)

10.0.25398.0 to < 10.0.25398.2274

Affected
Microsoft
Windows Server 2025

10.0.26100.0 to < 10.0.26100.32690

Affected
Microsoft
Windows Server 2025 (Server Core installation)

10.0.26100.0 to < 10.0.26100.32690

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.