CVE-2026-32202 actively exploited after April 27 advisory fix, exposing NTLMv2 hashes via zero-click SMB authentication.
Signal mentioned the upcoming changes amid reports that Russian state-sponsored hackers have been successfully using phishing ...