U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog


U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
April 29, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the catalog:

  • CVE-2024-1708 (CVSS score of 8.4) ConnectWise ScreenConnect Path Traversal Vulnerability
  • CVE-2026-32202 (CVSS score of 4.3) Microsoft Windows Protection Mechanism Failure Vulnerability

CVE-2024-02-21 is a path traversal vulnerability affecting ConnectWise ScreenConnect versions 23.9.7 and earlier. The issue stems from improper restriction of file paths, allowing attackers to access files and directories outside the intended scope.

By exploiting this flaw, an attacker could manipulate file paths to reach sensitive areas of the system. In certain scenarios, this may lead to remote code execution or unauthorized access to confidential data and critical resources, posing a serious risk to affected environments.

The second flaw added to the catalog is a Windows Shell Spoofing vulnerability tracked as CVE-2026-32202. The flaw allows attackers to spoof content over a network due to a failure in built-in protection mechanisms.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by May 12, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Strike action is planned for 3 and 4 March, and 7-17 March 2026. Discussions with UNISON are ongoing.

We have made a clear and constructive offer to establish a union recognition agreement, following the standard process led by Acas. As part of our offer, a final agreement on recognition would be subject to a whole-staff ballot. This is to ensure all staff have a say in this important decision.

Regarding pay, we cannot offer any uplift for the financial year 2025/2026 as this would put our service delivery at unacceptable risk and is not sustainable. We have made our tight financial situation clear to UNISON at every stage of our negotiations.

Our clients’ wellbeing continues to be our priority

While we respect the right of union members to take lawful industrial action, our focus remains on maintaining safe, continuous support for the people who rely on our services every day.

We are working with our teams to put our updated business continuity plans into action. Team managers and senior leaders are supporting colleagues, and despite strike action, services are continuing with minimal disruption. 

We remain committed to resolving this dispute and we are working with UNISON, via Acas, to see if we can resolve our differences.

This is not without its challenges, particularly at this time of year, and we are grateful to our hundreds of colleagues and clients for their understanding and support. 

If people have questions or concerns, they can contact us on 0117 909 6630 or email reception@second-step.co.uk. You can also visit our Answers to key questions about the strike page for more information.

For media queries, please contact PR & Communications Manager Jane Edmonds on 07841777401 or email jane.edmonds@second-step.co.uk. For out-of-hours queries, please call 07846377292.



Source link