Incomplete fix produces a new Windows shortcut vulnerability

Akamai has documented CVE-2026-32202, a Windows Shell vulnerability that stems from an incomplete fix for an earlier flaw, CVE-2026-21510. The original issue was exploited by APT28 through specially crafted LNK shortcut files. The new vulnerability arises because the handling and validation of file paths and metadata in LNK processing still does not fully sanitise externally controlled input. As a result, an attacker can craft LNK files that execute malicious content with minimal user interaction.

What this means for your organisation

Shortcut files do not read as dangerous to most people, and they pass through email, USB drives and shared folders without raising an eyebrow. When exploitation requires almost no action from the user, awareness training stops working as the sole defence. The more striking element is the repetition: this is the second time the same functionality has needed fixing, and an actor at APT28's level has already shown it is worth using.

Berigo recommends

  • Deploy Microsoft's update for CVE-2026-32202 across all clients, not just servers.
  • Block LNK files in email attachments and on file shares that receive content from outside.
  • Set up detection for shortcut files that launch command line tools or scripts.
  • Verify that devices outside central management actually receive the update, and deal with those that do not.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch