logo

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

ID: fb52838d-5f73-5fe7-b035-537d1755d1bd

STIX ID: report--fb52838d-5f73-5fe7-b035-537d1755d1bd

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: [email protected] (The Hacker News)

...
...

CISA added two vulnerabilities—CVE-2024-1708 (ConnectWise ScreenConnect, CVSS 8.4) and CVE-2026-32202 (Microsoft Windows Shell, CVSS 4.3)—to its Known Exploited Vulnerabilities list after evidence of active exploitation. The advisory notes these flaws have been chained with other critical bugs (notably CVE-2024-1709) and links attacks to APT28 and a China-based actor tracked as Storm-1175, which has deployed Medusa ransomware; federal agencies are required to patch by May 12, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.