BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CISA adds ConnectWise, Microsoft flaws to exploit

US adds exploited ConnectWise and Windows flaws to urgent threat catalog.

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited software flaws to its high-threat catalog on April 29, 2026.
  • The new entries include CVE-2024-1708, a path traversal bug in ConnectWise ScreenConnect, and CVE-2026-32202, a protection failure in Microsoft Windows Shell.
  • The Windows flaw, which originated from an incomplete patch for a prior zero-day, has been exploited by the Russian hacking group APT28 since late 2025.

On April 29, 2026, the U.S. Cybersecurity and Infrastructure Security Agency urgently updated its catalog of actively exploited threats, adding two critical vulnerabilities in widely used enterprise software. This action was based on confirmed evidence of active exploitation by malicious actors.

- Advertisement -

The first vulnerability, CVE-2024-1708, is a path traversal flaw in ConnectWise ScreenConnect that could permit remote code execution. The second, CVE-2026-32202, is a protection mechanism failure in Microsoft Windows Shell allowing network spoofing.

Microsoft updated its advisory to acknowledge active exploitation of the Windows flaw just a day before the CISA listing. However, the company has not publicly detailed the specific attacks leveraging the Shell vulnerability.

According to Akamai, CVE-2026-32202 stemmed from an incomplete patch for another vulnerability, CVE-2026-21510. Consequently, this flaw was exploited as a zero-day by the Russian group APT28 alongside CVE-2026-21513 in attacks since December 2025.

Meanwhile, exploitation of the ConnectWise ScreenConnect bug, CVE-2024-1708, has been chained with a critical authentication bypass (CVE-2024-1709) for years. Earlier in April 2026, Microsoft linked these flaws to the China-based threat actor Storm-1175 in ransomware attacks.

- Advertisement -

Federal Civilian Executive Branch agencies are now required to apply necessary patches by May 12, 2026. This mandate aims to secure networks against these documented and ongoing threats.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Drake’s New Song Demands Pardon for SBF

Drake called for the release of imprisoned FTX founder Sam Bankman-Fried in a lyric...

NIO’s Onvo L80 SUV Launches, Deliveries Start Saturday

Nio's mass-market subsidiary, Onvo, officially launched the L80 family SUV on Friday, with deliveries...

Liberland Honors Ethereum Founder Buterin With Star-Shaped Medal

Vitalik Buterin received the "First Class Order of Merit of the Star of Liberland"...

Firm seeks $344M in frozen Tether tied to Iran

Gerstein Harrow LLP is seeking a court order to compel Tether to release over...

Turla’s Kazuar Malware Evolves Into Stealthy P2P Botnet

The Russian state-sponsored group Turla (aka Secret Blizzard) has evolved its Kazuar malware into...

Must Read

Crypto in New York: The 2026 Guide to Legal Exchanges and BitLicense Regulations

TL;DR: Trading crypto in New York is legal but heavily regulated by the New York Department of Financial Services (NYDFS). Platforms must hold a BitLicense...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading