CVE-2026-32202: listed in the CISA KEV catalog
CVE-2026-32202 · CVSS 4.3 MEDIUM · EPSS 64% · KEV 2026-04-28 · patch available
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Is CVE-2026-32202 exploited?
- Listed in the CISA KEV catalog on 2026-04-28.
- Federal remediation due 2026-05-12.
- Past that date by 95 days.
- EPSS puts exploitation in the next 30 days at 64%.
- Public exploit code: proof of concept.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
What PlainSec published about CVE-2026-32202
Primary sources
What this record does not say
- No affected package data.
KEV and EPSS are re-checked daily. Record last updated 2026-08-11.