New Windows flaw stems from incomplete fix for APT28-exploited bugs SecurityWeek reports that Microsoft's deficient February patch for the high-severity Windows SmartScreen and Shell prompt bypass bug CVE-2026-21510, which has been exploited by the Russia-linked advanced persistent threat group APT28, has resulted in the new authentication coercion zero-click bug, tracked as CVE-2026-32202.