Microsoft confirmed that CVE-2026-32202, a patched Windows Shell spoofing flaw, has been actively exploited in the wild after initially publishing incorrect exploitability information. The vulnerability is a zero-click authentication coercion issue tied to an incomplete fix for CVE-2026-21510 and can be triggered when Windows Explorer processes a malicious .LNK file. Researchers said the shortcut’s crafted LinkTargetIDList can force the system to resolve an attacker-controlled UNC path, causing an outbound SMB connection and NTLM authentication attempt before SmartScreen trust checks occur.
Akamai and CERT-UA linked the activity to APT28, which used weaponized LNK files in campaigns against Ukraine and several EU countries beginning in December 2025, chaining CVE-2026-21513 with CVE-2026-21510 for code execution and then abusing the residual flaw to capture Net-NTLMv2 hashes for relay attacks or offline cracking. Microsoft addressed CVE-2026-32202 in its April 2026 Patch Tuesday release, and defenders were urged to patch quickly, monitor outbound SMB traffic, and reduce or harden NTLM usage to limit follow-on credential abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-29, CISA added Microsoft Windows Shell flaw CVE-2026-32202 to its Known Exploited Vulnerabilities catalog. The agency directed U.S. federal civilian agencies to remediate the issue under Binding Operational Directive 22-01 by 2026-05-12.
Notepad++ addressed CVE-2026-3008 in version 8.9.4. The update remediated the string-injection issue in the localization parser and also included additional bug fixes and stability improvements.
By April 28, 2026, Microsoft revised its advisory to state that CVE-2026-32202 had been actively exploited in the wild. Reporting tied the flaw to prior APT28 tradecraft and highlighted the risk of zero-click NTLM hash leakage when victims merely browse to a folder containing a malicious LNK file.
A format string injection flaw affecting Notepad++ 8.9.3, tracked as CVE-2026-3008, was reported through CSA's Responsible Vulnerability Disclosure Policy, with Hazley Samsudin credited for identifying it. The bug could leak memory contents or crash the application via crafted localization data.
On 2026-04-23, Akamai published technical analysis showing that attackers could craft Windows LNK files using the LinkTargetIDList structure to mimic Control Panel objects and embed a UNC path to an attacker-controlled CPL module. The write-up explained how shell32.dll and Windows Explorer process the shortcut in a way that can trigger outbound SMB authentication and support the CVE-2026-32202 exploitation chain.
In April 2026 Patch Tuesday, Microsoft released a patch for CVE-2026-32202, a zero-click Windows Shell vulnerability that can coerce a victim system into authenticating to an attacker-controlled SMB server when a malicious file is processed. The issue can expose Net-NTLMv2 hashes for relay attacks or offline cracking.
On April 14, 2026, Microsoft initially published advisory information for CVE-2026-32202 with incorrect exploitability details. The flaw is a Windows Shell spoofing and authentication coercion issue stemming from the incomplete fix for CVE-2026-21510.
In February 2026, Microsoft fixed the original remote code execution path for CVE-2026-21510 by adding SmartScreen trust verification. Researchers later found the fix was incomplete because Windows icon extraction still triggered outbound SMB connections and NTLM authentication before trust checks.
Beginning in December 2025, the Russian state-linked group APT28 used weaponized LNK files to target Ukraine and several EU countries. The campaign chained CVE-2026-21513 with CVE-2026-21510 to bypass SmartScreen, load remote content over UNC paths, and achieve code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethecyberexpress.com
Open sourcethehackernews.com
Open sourcecvereports.com
Open sourceakamai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.