Story perspectives
Microsoft Windows Shell Flaw (CVE-2026-32202) Added to CISA Catalog
4/30/2026
1 of 1
Story summary
- Microsoft disclosed CVE-2026-32202 on April 14 as an authentication coercion flaw in Windows Shell that can expose data via network spoofing.
- Akamai senior security researcher Maor Dahan reported the flaw, saying it stemmed from an incomplete fix for CVE-2026-21510.
- Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog on April 15 and gave federal agencies a May 12 deadline to remediate it.
