Why the flaw stood out
CISA added CVE-2026-32202 to its Known Exploited Vulnerabilities catalogue in late April. Akamai's original research showed how the Windows flaw could expose an NTLM authentication hash with little or no normal user interaction, which is why it was described as zero-click.
What an NTLM hash leak can enable
An NTLM hash is not the plain password, but attackers may try to crack it or relay the authentication to another service. The risk becomes greater where older authentication remains widely accepted and outbound connections are not restricted.
Patch supported Windows devices and verify restart.
Block outbound SMB where it is not required.
Reduce NTLM and separate privileged accounts.
Your response plan
Include laptops outside the office.
Prioritise exposed and privileged users.
Do not rely on a deployment command alone.
Track remaining NTLM dependencies.
Apply Microsoft's update, then check whether the vulnerable systems actually restarted and reached the fixed build. Reduce NTLM use where possible, require stronger authentication, block unnecessary outbound SMB traffic, and protect privileged accounts from ordinary browsing and email.
Do not wait for a user-training fix
- Remote devices have checked in and restarted.
- Outbound SMB is restricted at the edge.
- Privileged accounts do not handle routine email.
- NTLM exceptions have owners and retirement dates.
Awareness training is valuable, but it cannot solve a flaw that does not depend on an obvious click. This incident called for technical controls, rapid patching, and a plan to retire older authentication paths.
