logo

CISA Identifies Active Vulnerabilities in ConnectWise and Windows Systems

ID: e6441044-627d-5785-9965-3c202a38a15e

STIX ID: report--e6441044-627d-5785-9965-3c202a38a15e

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-05-01

Date Updated: 2026-05-02

...
...

CISA has added two high-severity vulnerabilities to its KEV catalog: a ConnectWise remote code execution flaw caused by poor authentication and a Windows kernel privilege escalation that is being actively exploited. Patches are available for both issues, but many systems remain unpatched, so administrators are strongly urged to apply updates immediately to mitigate significant risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.