CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
ID: fb52838d-5f73-5fe7-b035-537d1755d1bd
STIX ID: report--fb52838d-5f73-5fe7-b035-537d1755d1bd
Feed Name: The Hacker News
CISA added two vulnerabilities—CVE-2024-1708 (ConnectWise ScreenConnect, CVSS 8.4) and CVE-2026-32202 (Microsoft Windows Shell, CVSS 4.3)—to its Known Exploited Vulnerabilities list after evidence of active exploitation. The advisory notes these flaws have been chained with other critical bugs (notably CVE-2024-1709) and links attacks to APT28 and a China-based actor tracked as Storm-1175, which has deployed Medusa ransomware; federal agencies are required to patch by May 12, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
