Microsoft published security advisories for several Windows spoofing vulnerabilities affecting core platform components, including Windows Shell Link Processing (CVE-2026-25185), Windows SMB Server (CVE-2025-48802), Windows NTLM (CVE-2025-21217), Virtual Secure Mode (CVE-2025-48813), and Windows Certificate handling (CVE-2022-21836). The flaws span identity, file handling, network services, virtualization-backed security, and certificate trust mechanisms, indicating broad exposure across enterprise Windows environments.
The advisories identify spoofing as the common impact, a class of weakness that can let attackers misrepresent files, systems, identities, or trust relationships to users and services. Organizations relying on Windows authentication, SMB-based file sharing, shortcut handling, certificate validation, and virtualization-based protections should review the affected CVEs and apply Microsoft security updates to reduce the risk of impersonation, deceptive content delivery, and trust bypass in managed environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide advisory for CVE-2026-25185, a Windows Shell Link Processing Spoofing Vulnerability.
Microsoft released a Security Update Guide entry for CVE-2025-48813, a Virtual Secure Mode Spoofing Vulnerability.
Microsoft published a Security Update Guide entry for CVE-2025-48802, a Windows SMB Server Spoofing Vulnerability.
Microsoft released a Security Update Guide entry for CVE-2025-21217, a Windows NTLM Spoofing Vulnerability.
Microsoft published security guidance for CVE-2022-21836, a Windows Certificate Spoofing Vulnerability.
6 references tracked. Mallory keeps watching after this page renders.
synacktiv.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceportal.msrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.