Windows zero-day CVE-2026-32202 confirmed as exploited
… CISA added CVE-2026-32202 to its Known Exploited Vulnerabilities catalog today, ordering US federal agencies to patch by May 12. The flaw exists because Microsoft's February 2026 fix for a related vulnerability left an authentication gap that attackers have since used. …