New Windows Shell 0-Click Vulnerability Exploited to Bypass Defender SmartScreen
A critical zero-click authentication coercion vulnerability, tracked as CVE-2026-32202, stemming from an incomplete patch for a Windows Shell security feature bypass actively weaponized by the Russian APT28 threat group. Microsoft confirmed active exploitation of the flaw and released a fix as part of its April 2026 Patch Tuesday update. According to CERT-UA, the APT28 threat actor, also known […] The post New Windows Shell 0-Click Vulnerability Exploited to Bypass Defender SmartScreen appeared first on Cyber Security News.
A zero-click authentication coercion vulnerability (CVE-2026-32202) in Windows Shell was exploited by the Russian APT28 threat group, allowing bypass of Defender SmartScreen, and has been actively weaponized since April 2026.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NRead the full article
This is a curated summary. The complete article is available at Cyber Security News.
