Medium Known exploited (KEV) CVE-2026-32202

Windows Shell Spoofing Vulnerability Added to CISA KEV (CVE-2026-32202)

Microsoft Windows Added to KEV Apr 28, 2026 Federal remediation due 2026-05-12

Microsoft's Windows Shell contains a protection mechanism failure (a flaw where a safeguard that should work does not function as intended) that can be abused for network-based spoofing (impersonation). CISA has added it to its Known Exploited Vulnerabilities (KEV) catalog of flaws confirmed to be exploited in the wild.

Key facts

  • CVE IDCVE-2026-32202
  • CVSS base score4.3 MEDIUM
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
  • Affected (vendor / product)Microsoft Windows
  • CWECWE-693
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-05-12 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Affects Microsoft Windows (Windows Shell); the weakness type is a protection mechanism failure (a safeguard that should work does not function correctly).
  • An unauthorized attacker could perform spoofing (impersonation or deceptive display) over a network.
  • NVD rates the severity at CVSS 3.1 4.3 (Medium); exploitation requires user interaction (UI:R).
  • CISA added it to the KEV catalog (vulnerabilities confirmed exploited in the wild) on April 28, 2026, with a remediation due date of May 12, 2026.
  • Even with a moderate score, KEV's principle is to prioritize remediation once exploitation is confirmed.
  • Spoofing does little alone, but combined with phishing it misleads a user judgement into real harm.

1Windows Shell as the point of contact

Windows Shell is a central part of Windows that underpins how people operate their computers, including the desktop and File Explorer. A protection mechanism failure means that a safeguard meant to prevent improper actions or deception does not function as intended. Because of this flaw, an attacker could carry out spoofing over a network, presenting deceptive displays or information that appear to be legitimate.

2An attack that needs user interaction

NVD rates the severity at CVSS 4.3 (Medium), and exploitation requires some action by the user (UI:R). While the score is moderate, what matters most here is that the vulnerability appears in CISA's KEV catalog. KEV lists only vulnerabilities that have been confirmed as actually used in attacks, not merely theoretical risks, so inclusion signals that remediation should be a high priority.

3How spoofing misleads judgment

Spoofing on its own does not always cause major harm, but by misleading a user's judgment with a deceptive display it can lead to real damage when combined with techniques such as phishing (tricking people into giving up information by posing as a trusted site or sender).

For U.S. federal agencies, Binding Operational Directive (BOD) 22-01 requires applying mitigations per the vendor's instructions, and if mitigations are not available, discontinuing use of the affected product is presented as an option. The core idea behind KEV is that even a moderate score warrants prompt action once exploitation has been confirmed.

4Small alone, effective in combination

Spoofing does not necessarily produce great damage on its own. Combined with other techniques, though, the distance to real harm closes quickly.

Spoofing aloneSpoofing combined with other techniques
No data is taken directlyA false display leads the user to judge wrongly
CVSS stops at 4.3 (medium)Together with phishing it reaches real harm
Easy to defer in prioritisationBeing on KEV means a record of actual use exists
The attack needs a user actionDrawing out that action is what the deception is for

Windows Shell is the core part underlying how a user operates the machine — the desktop, Explorer and so on. Protection mechanism failure means the safeguards built in to prevent improper operations and impersonation do not work as intended. Even at a middling score, once exploitation is confirmed a prompt response is required; that is the basic posture of KEV.

Why it matters

Because Windows Shell is a foundational component used routinely across many environments, the potential scope is broad. Spoofing can mislead users with deceptive displays and, combined with techniques like phishing, can contribute to outcomes such as information theft. Since KEV inclusion means exploitation has been confirmed, organizations are advised to treat applying the vendor's mitigations as a high priority.

FAQ

What is spoofing?
Spoofing is impersonating something legitimate to present deceptive displays or information that mislead a user's judgment. It can lead to real harm when combined with techniques such as phishing (posing as a trusted source to trick people into giving up information).
If the CVSS score is Medium (4.3), why does it matter?
Because the vulnerability is listed in CISA's KEV catalog, meaning it has been confirmed as actually used in attacks. Even a moderate score warrants priority attention once exploitation is confirmed.
What action is required?
Apply mitigations according to the vendor's (Microsoft's) instructions. For U.S. federal agencies, Binding Operational Directive BOD 22-01 applies, and if mitigations are not available, discontinuing use of the affected product is presented as an option.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#CISA KEV#Microsoft#Windows#Windows Shell#Spoofing#Protection Mechanism Failure#BOD 22-01
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.