logo

U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

ID: d951ca84-a291-5a01-a99b-7e3bfe1d536a

STIX ID: report--d951ca84-a291-5a01-a99b-7e3bfe1d536a

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Pierluigi Paganini

...
...

CISA added two flaws to its Known Exploited Vulnerabilities catalog: a high-severity ConnectWise ScreenConnect path traversal (CVE-2024-1708, CVSS 8.4) that can allow access to files or potentially lead to RCE, and a lower-severity Windows Shell protection-failure/spoofing vulnerability (CVE-2026-32202, CVSS 4.3). Federal civilian agencies are ordered to remediate the issues by May 12, 2026; organizations are advised to review the KEV catalog and patch affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.