logo

Validating the Bishop Fox Findings in ConnectWise Control | Huntress

ID: 21f7b2d4-aba7-50ef-9de6-c1e8480ce135

STIX ID: report--21f7b2d4-aba7-50ef-9de6-c1e8480ce135

Feed Name: Huntress Blog

Threat Score
60/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

**Executive Summary:** Bishop Fox disclosed eight vulnerabilities in ConnectWise Control including stored XSS, CORS misconfiguration, CSRF, PII and user-enumeration disclosures, a malicious-extension remote code execution, missing security headers, and insecure cookie scope; the report summarizes each finding, assigns CVEs where applicable, and documents ConnectWise’s mitigating actions (some fully mitigated, some partially mitigated, and some still pending).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.