CVE-2026-32202

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

  • Published Apr 14, 2026
  • CVSS 4.3 medium
  • 4.9% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • Public exploit code is available

Affected software

CVE-2026-32202 at the National Vulnerability Database