INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Actively Exploited Windows Flaws Found in ConnectWise and KEV

| 2026-04-29 08:46 CRITICAL HIGH
Executive Summary AI-generated
The vulnerability exploited by the Russian hacking group APT28 in attacks targeting Ukraine and E.U. countries since December 2025 is a zero-day flaw that has been linked to an incomplete patch for CVE-2026-21510, which was also used as a zero-day exploit alongside CVE-2026-21513 by the same threat actor. This vulnerability has now been added to Microsoft Windows Shell and ConnectWise ScreenConnect flaws, making it a known exploited vulnerability in both products.
Technical Mitigations AI-generated
* Implement secure file paths: Ensure that all file paths on the system are properly restricted to prevent attackers from accessing sensitive areas of the system. This can be achieved by using a combination of access control lists (ACLs), permissions, and network security groups. * Regularly update Windows and ConnectWise ScreenConnect: Keep Microsoft Windows and ConnectWise ScreenConnect up-to-date with the latest security patches and updates to ensure that any known vulnerabilities are patched before they can be exploited. * Use a secure authentication mechanism: Implement strong authentication mechanisms, such as multi-factor authentication (MFA), to prevent unauthorized access to sensitive areas of the system. This can help reduce the risk of authentication bypass attacks. * Monitor network traffic and logs: Regularly monitor network traffic and log files for suspicious activity that may indicate an attack exploiting CVE-2024-1708 or CVE-2026-32202. This can help identify potential security threats early on. * Implement a web application firewall (WAF): Consider implementing a WAF to protect against common web attacks, such as SQL injection and cross-site scripting (XSS). A well-configured WAF can help prevent attackers from exploiting vulnerabilities like CVE-2024-1708 or CVE-2026-32202.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28 CVE-2024-1708CVE-2024-1708 CVE-2026-32202CVE-2026-32202 CVE-2026-21510CVE-2026-21510 CVE-2026-21513CVE-2026-21513 CVE-2024-1709CVE-2024-1709
Target & Sectors
RU CN UA
Incident Timeline
‎February 2024
Threat actors used a vulnerability in Microsoft Windows Shell to exploit Actively Exploited ConnectWise and Windows Flaws.
vulnerability CVE-2026-32202
infrastructure 4.3
organisation CVE-2026
general_metric 4.3 score
infrastructure Windows
organisation Microsoft Windows Shell
‎February 22, 2024
Threat actors exploited Actively Exploited ConnectWise and Windows vulnerabilities to target KEV systems.
vulnerability CVE-2024-1709
‎December 2025
Threat actors used a malicious Windows Shortcut (LNK) file to exploit CVE-2024-1709, a critical authentication bypass vulnerability in Windows.
source_region Russian Federation
target_region Ukraine
vulnerability CVE-2026-21510
vulnerability CVE-2026-21513
organisation Akamai
threat_actor APT28
general_metric 21513 CVE-2026
infrastructure Windows
organisation CVE-2026-21510 Exploitation The campaign
organisation Windows Shortcut
organisation CVE-2024-1709
‎January 2026
Threat actors used CVE-2026-21513 to target APT28.
vulnerability CVE-2026-21513
threat_actor APT28
‎February 2026
Threat actors used a vulnerability in ConnectWise and Windows to exploit CVE-2026-21513, allowing them to authenticate to an attacker's server without user interaction.
organisation CVE-2026-21513
general_metric 8.8 latter
infrastructure 8.8
organisation Akamai
tactic Remote Code Execution
organisation SmartScreen
organisation CPL
organisation SMB
‎2026/03/29
Threat actors used CVE-2026-21513 to target ConnectWise systems.
vulnerability CVE-2026-21513
threat_actor APT28
‎April 2026
The incident involved the addition of CVE-2026-32202 to the KEV catalog by CISA, which was followed by Microsoft's update acknowledging that the flaw had been actively exploited.
organisation KEV
organisation Microsoft
‎April 14
Threat actors used a vulnerability in ConnectWise to target Microsoft Windows.
organisation CVSS
‎April 27, 2026
Threat actors used a vulnerability in ConnectWise to target Windows systems.
organisation CVSS
‎Apr 28, 2026
Threat actors used a vulnerability in ConnectWise to target Windows systems.
‎Apr 29, 2026
Threat actors exploited the Actively Exploited ConnectWise vulnerability to target Windows systems.
‎2026/04/29
Microsoft Windows Shell flaw CVE-2026-32202 exploited by APT28.
threat_actor APT28
organisation GruesomeLarch
infrastructure Windows
organisation DLL
organisation UNC
organisation Microsoft
infrastructure 23.9.7
organisation ConnectWise ScreenConnect
organisation CVSS
organisation NTLM
organisation LNK
‎May 12, 2026
Threat actors used a vulnerability in ConnectWise to exploit Windows flaws.
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎4.3
Software Version
Metrics
infrastructure
‎23.9.7
Software Version
Metrics
infrastructure
‎8.8
Software Version