Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
    Cybersecurity

    CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

    adminBy adminApril 29, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 29, 2026Vulnerability / Network Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

    The vulnerabilities are listed below –

    • CVE-2024-1708 (CVSS score: 8.4) – A path traversal vulnerability in  ConnectWise ScreenConnect that could allow an attacker to execute remote code or directly impact confidential data and critical systems. (Fixed in February 2024)
    • CVE-2026-32202 (CVSS score: 4.3) – A protection mechanism failure vulnerability in  Microsoft Windows Shell that could allow an unauthorized attacker to perform spoofing over a network. (Fixed in April 2026)

    The addition of CVE-2026-32202 to the KEV catalog comes a day after Microsoft updated its advisory for the flaw to acknowledge it had come under active exploitation.

    Although Microsoft has not disclosed the nature of the attacks weaponizing the flaw, Akamai said the vulnerability stemmed from an incomplete patch for CVE-2026-21510, which was exploited as a zero-day alongside CVE-2026-21513 by the Russian hacking group APT28 in attacks targeting Ukraine and E.U. countries since December 2025.

    Attacks exploiting CVE-2024-1708, on the other hand, have been chained with CVE-2024-1709 (CVSS score: 10.0), a critical authentication bypass vulnerability, by multiple threat actors over the years. Earlier this month, Microsoft linked the exploitation of the flaws to a China-based threat actor it tracks as Storm-1175 in attacks deploying Medusa ransomware.

    It’s worth noting that CISA added CVE-2024-1709 to the KEV catalog on February 22, 2024. Federal Civilian Executive Branch (FCEB) agencies are required to apply the necessary fixes by May 12, 2026, to secure their networks.

    Actively adds CISA ConnectWise Exploited Flaws KEV Windows
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleHow to measure paid social’s impact on PPC
    Next Article 9 Best WordPress Consulting Themes to Win More Clients (20+ Tested)
    admin
    • Website

    Related Posts

    Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug

    May 1, 2026

    New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

    May 1, 2026

    AI traffic is getting bigger, louder, and less predictable

    May 1, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug

    May 1, 2026

    Google Preferred Sources now works for all languages

    May 1, 2026

    New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

    May 1, 2026

    AI traffic is getting bigger, louder, and less predictable

    May 1, 2026
    Categories
    • Blogging (71)
    • Cybersecurity (1,613)
    • Privacy & Online Earning (193)
    • SEO & Digital Marketing (997)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (258)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug

    May 1, 2026

    Google Preferred Sources now works for all languages

    May 1, 2026

    New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

    May 1, 2026
    Most Popular
    • Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug
    • Google Preferred Sources now works for all languages
    • New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
    • AI traffic is getting bigger, louder, and less predictable
    • AI Gives You The Vocabulary. It Doesn’t Give You The Expertise
    • Romanian leader of online swatting ring gets 4 years in prison
    • When 170,000 people show up: Network refresh readies Churchill Downs for Kentucky Derby
    • AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.