The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their Windows systems against a vulnerability exploited in zero-day attacks. Tracked as CVE-2026-32202, this security flaw was reported by cybersecurity firm Akamai, which described it as a zero-click NTLM hash leak vulnerability left behind after Microsoft incompletely patched a remote code execution flaw (CVE-2026-21510) in February. As CERT-UA revealed, the Russian APT28 (aka UAC-0001 and Fancy Bear) cyberespionage group exploited CVE-2026-21510 in attacks against Ukraine and EU countries in December 2025 as part of an exploit chain that also targeted a LNK file flaw (CVE-2026-21513). Microsoft says that remote attackers who successfully exploit the CVE-2026-32202 vulnerability in low-complexity attacks by sending "the victim a malicious file that the victim would have to execute," could "view some sensitive information" on unpatched systems. Akamai further explained in a Thursday report that this security flaw can be exploited in pass-the-hash attacks to steal NTLM hashes (hashed passwords), which are later used to authenticate as the compromised user, allowing attackers to spread laterally across the network or steal sensitive data. Microsoft also flagged the CVE-2026-3220 flaw as exploited in attacks on Sunday after BleepingComputer reached out last week to ask why the advisory released during the April 2026 Patch Tuesday had an exploitability assessment of 'Exploita...
CISA orders feds to patch Windows flaw exploited as zero-day
BleepingComputer
·Sergiu Gatlan
·Published Apr 29, 2026
·Updated
Affected Software
1 affected component
Microsoft Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses CISA's directive for federal agencies to address a Windows vulnerability exploited in zero-day attacks.
2
What security implications are discussed in the article?
The article highlights the risk posed by the CVE-2026-32202 vulnerability which can be exploited by attackers in zero-day incidents.
3
What specific vulnerability is mentioned in the article?
The article references CVE-2026-32202 as the critical vulnerability affecting Microsoft Windows.
4
Who reported the vulnerability mentioned in this article?
The vulnerability was reported by the cybersecurity firm Akamai.
5
What actions has CISA mandated regarding Windows systems?
CISA has mandated that federal agencies patch their Windows systems to secure them against the identified zero-day vulnerability.