CVE-2026-32202: listed in the CISA KEV catalog
CVE-2026-32202 · CVSS 4.3 MEDIUM · EPSS 5% · KEV 2026-04-28 · patch available
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Is CVE-2026-32202 exploited?
- Listed in the CISA KEV catalog on 2026-04-28.
- Federal remediation due 2026-05-12.
- Past that date by 141 days.
- EPSS puts exploitation in the next 30 days at 5%.
- Public exploit code: proof of concept.
Which products and versions are affected?
- Microsoft · Windows 10 · Version 21H2
- Microsoft · Windows 10 · Version 1809
- Microsoft · Windows 10 · Version 1607
- Microsoft · Windows 11 · version 26H1
- Hitachi · Virtual Storage Platform · 5200
- Hitachi · Virtual Storage Platform · 5100
- Hitachi · Virtual Storage Platform · 5500
- Microsoft · Windows 11 · Version 25H2
- Hitachi · Virtual Storage Platform · 5100H
- Hitachi · Virtual Storage Platform · 5500H
- Microsoft · Windows 11 · Version 24H2
- Microsoft · Windows 10 · Version 22H2
- Microsoft · Windows Server 2022 · 23H2 Edition
- Microsoft · Windows 11 · Version 23H2
- Hitachi · Virtual Storage Platform · 5600H
- Hitachi · Virtual Storage Platform · 5200H
- Hitachi · Virtual Storage Platform · 5600
- Microsoft · Windows 10 Version 1809 for 32-bit Systems · < 10.0.17763.8644
- Microsoft · Windows 10 Version 1809 for x64-based Systems · < 10.0.17763.8644
- Microsoft · Windows Server 2019 · < 10.0.17763.8644
- Microsoft · Windows Server 2022 (Server Core installation) · < 10.0.20348.5020
- Microsoft · Windows 10 Version 21H2 for 32-bit Systems · < 10.0.19044.7184
- Microsoft · Windows 10 Version 21H2 for ARM64-based Systems · < 10.0.19044.7184
- Microsoft · Windows 10 Version 21H2 for x64-based Systems · < 10.0.19044.7184
- Microsoft · Windows Server 2025 · < 10.0.26100.32690
- Microsoft · Windows Server 2025 (Server Core installation) · < 10.0.26100.32690
- Microsoft · Windows 11 Version 25H2 for ARM64-based Systems · < 10.0.26200.8246
- Microsoft · Windows 11 Version 25H2 for x64-based Systems · < 10.0.26200.8246
- Microsoft · Windows 11 Version 23H2 for ARM64-based Systems · < 10.0.22631.6936
- Microsoft · Windows 11 Version 23H2 for x64-based Systems · < 10.0.22631.6936
- Microsoft · Windows Server 2022, 23H2 Edition (Server Core installation) · < 10.0.25398.2274
- Microsoft · Windows 10 Version 1607 for 32-bit Systems · < 10.0.14393.9060
- Microsoft · Windows 10 Version 1607 for x64-based Systems · < 10.0.14393.9060
- Microsoft · Windows Server 2016 · < 10.0.14393.9060
- Microsoft · Windows Server 2012 · < 6.2.9200.26026
- Microsoft · Windows Server 2012 (Server Core installation) · < 6.2.9200.26026
Is there a patch?
What PlainSec published about CVE-2026-32202
Primary sources
KEV and EPSS are re-checked daily. Record last updated 2026-09-24.