Windows CVE-2026-32202 Exploited in the Wild
The current exploits are targeting CVE-2026-32202, a bug in the Windows Shell that allows an attacker to gain access to some sensitive data on the target network.

The current exploits are targeting CVE-2026-32202, a bug in the Windows Shell that allows an attacker to gain access to some sensitive data on the target network.
April 29, 2026 | 2 min read

Attackers are actively exploiting a serious Windows vulnerability that resulted from an incomplete fix for a previous bug that had been exploited by the Russian Fancy Bear APT.
The current exploits are targeting CVE-2026-32202, a bug in the Windows Shell that allows an attacker to gain access to some sensitive data on the target network.
“An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality) but not all resources within the impacted component may be divulged to the attacker. The attacker cannot make changes to disclosed information (Integrity) or limit access to the resource (Availability),” the Microsoft advisory says.
Microsoft released a patch for the flaw on April 14 as part of the monthly Patch Tuesday updates, but at the time it had not been exploited. On April 27, Microsoft confirmed that the bug has been exploited in the wild. There is no public information about the scope of exploitation or which threat actors are targeting the vulnerability yet.
However, the initial vulnerability in this saga that eventually led to the discovery of CVE-2026-32202 was exploited, along with another bug (CVE-2026-21513) as a zero day by Fancy Bear in a campaign against targets in Ukraine in late 2025. Microsoft patched that flaw (CVE-2026-21510) in February, but the patch wasn’t complete, leading to the discovery of CVE-2026-32202.
“The second vulnerability (CVE-2026-21510) bypasses security features such as the Microsoft Defender SmartScreen and executes attacker-controlled code, which is stored on the attacker's remote server. APT28 leverages the Windows shell namespace parsing mechanism to load a dynamic link library (DLL) from a remote server using a UNC path. The DLL is loaded as part of the Control Panel (CPL) objects without proper network zone validation,” Akamai researcher Maor Dahan wrote in an analysis of the exploits.
“With the patch in place, the RCE is effectively mitigated and SmartScreen now blocks unsigned or untrusted CPLs from executing. However, while testing the patch, we noticed something interesting: The victim machine was still authenticating to the attacker's server.”
CVE-2026-32202 affects most current versions of Windows and Windows Server.
CISA has added the vulnerability to its Known Exploited Vulnerability catalog.
April 29, 2026 | 2 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.