Microsoft · Windows Shell · CVE-2026-32202
**Name of the Vulnerable Software and Affected Versions**
Microsoft Windows (affected versions not specified)
**Description**
A protection mechanism failure in the Windows Shell allows a remote unauthorized attacker to perform spoofing. The issue occurs when a malicious Windows shortcut or LNK path triggers an automatic SMB authentication attempt, which exposes the victim's Net-NTLMv2 hash for potential offline cracking or relay attacks. This flaw can be triggered without user interaction, such as when a user simply opens a folder containing a malicious shortcut. This issue has been actively exploited in the wild by APT28 (Fancy Bear) targeting Ukraine and EU nations as part of a larger exploit chain to steal credentials and download malicious code from remote servers.
**Recommendations**
Apply the security updates released in April 2026.