Windows zero-day CVE-2026-32202 confirmed as exploited
… The original flaw, CVE-2026-21510, was a Windows Shell protection mechanism failure exploited in attacks against Ukraine and EU countries in December 2025. Microsoft patched CVE-2026-21510 in February and marked it as actively exploited at the time. …