logo

CVE-2026-0695: High-Severity XSS Flaw Patched in ConnectWise PSA 2026.1

ID: 20a54586-1906-591a-af44-f0d9f4da1627

STIX ID: report--20a54586-1906-591a-af44-f0d9f4da1627

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

ConnectWise released PSA 2026.1 to fix two security issues affecting versions prior to 2026.1: CVE-2026-0695 (Stored XSS, CVSS 8.7) that allows malicious scripts via Time Entry notes, and CVE-2026-0696 (missing HttpOnly flag, CVSS 6.5) that exposes session cookies; together they can enable session hijacking. Cloud instances are being auto-updated; on-premises users must apply the 2026.1 patches and update desktop clients to remediate the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.