A Microsoft patch can leave the underlying flaw alive. CVE-2026-32202 is a Windows Shell spoofing zero-day that emerged from an incomplete fix for a previously exploited issue, so systems that were marked patched may still be exposed. FortiGuard says the new vulnerability affects Microsoft Windows Shell and ties back to earlier exploitation of the same weakness. The key point is not the disclosure itself. It is that remediation did not fully close the door, which makes patch status a weaker signal than usual. That changes the threat model for any environment that treated the earlier update as the end of the problem. The risk persists until the remediation is actually complete, not just installed.
Part of the PlainSec briefing for 2026-05-02