CVE-2026-32202Medium· 4.3▾ Midnight⚠ Exploited in the wildPoC availableProtection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 23.7 · likelihood 12.7 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due May 12, 2026
Last analysed / modified upstream
64%
Exploit-DB · 3 GitHub repos (last check)
Added to the CISA catalog on Apr 28, 2026. Federal remediation due May 12, 2026. View catalog ↗
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
windows_10_1607 < 10.0.14393.9060windows_10_1809 < 10.0.17763.8644windows_10_21h2 < 10.0.19044.7184windows_10_22h2 < 10.0.19045.7184windows_11_23h2 < 10.0.22631.6936windows_11_24h2 < 10.0.26100.8246windows_11_25h2 < 10.0.26200.8246windows_11_26h1 < 10.0.28000.1836windows_server_2012windows_server_2012 = r2windows_server_2016 < 10.0.14393.9060windows_server_2019 < 10.0.17763.8644windows_server_2022 < 10.0.20348.5020windows_server_2022_23h2 < 10.0.25398.2274windows_server_2025 < 10.0.26100.32690Upgrade past the affected range:
windows_10_1607 10.0.14393.9060windows_10_1809 10.0.17763.8644windows_10_21h2 10.0.19044.7184windows_10_22h2 10.0.19045.7184windows_11_23h2 10.0.22631.6936windows_11_24h2 10.0.26100.8246windows_11_25h2 10.0.26200.8246windows_11_26h1 10.0.28000.1836windows_server_2016 10.0.14393.9060windows_server_2019 10.0.17763.8644windows_server_2022 10.0.20348.5020windows_server_2022_23h2 10.0.25398.2274windows_server_2025 10.0.26100.32690Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-33824Critical· 9.8Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2018-8174High· 7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…
CVE-2026-20805Medium· 5.5Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
CVE-2026-20824Medium· 5.5Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-32225High· 8.8Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.