INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Actively Exploited Windows Flaws Found in ConnectWise and KEV

| 2026-04-29 08:46 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The vulnerability exploited by the Russian hacking group APT28 in attacks targeting Ukraine and E.U. countries since December 2025 is a zero-day flaw that has been linked to an incomplete patch for CVE-2026-21510, which was also used as a zero-day exploit alongside CVE-2026-21513 by the same threat actor. This vulnerability has now been added to Microsoft Windows Shell and ConnectWise ScreenConnect flaws, making it a known exploited vulnerability in both products.
Technical Mitigations AI-generated
* Implement secure file paths: Ensure that all file paths on the system are properly restricted to prevent attackers from accessing sensitive areas of the system. This can be achieved by using a combination of access control lists (ACLs), permissions, and network security groups. * Regularly update Windows and ConnectWise ScreenConnect: Keep Microsoft Windows and ConnectWise ScreenConnect up-to-date with the latest security patches and updates to ensure that any known vulnerabilities are patched before they can be exploited. * Use a secure authentication mechanism: Implement strong authentication mechanisms, such as multi-factor authentication (MFA), to prevent unauthorized access to sensitive areas of the system. This can help reduce the risk of authentication bypass attacks. * Monitor network traffic and logs: Regularly monitor network traffic and log files for suspicious activity that may indicate an attack exploiting CVE-2024-1708 or CVE-2026-32202. This can help identify potential security threats early on. * Implement a web application firewall (WAF): Consider implementing a WAF to protect against common web attacks, such as SQL injection and cross-site scripting (XSS). A well-configured WAF can help prevent attackers from exploiting vulnerabilities like CVE-2024-1708 or CVE-2026-32202.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

at•••••.com
pa•••••.cpl
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28 CVE-2024-1708CVE-2024-1708 CVE-2026-32202CVE-2026-32202 CVE-2026-21510CVE-2026-21510 CVE-2026-21513CVE-2026-21513 CVE-2024-1709CVE-2024-1709
Target & Sectors
RU CN UA
governmentgovernment
Incident Timeline
‎February 2024
Threat actors used a vulnerability in Microsoft Windows Shell to exploit Actively Exploited ConnectWise and Windows Flaws.
vulnerability CVE-2026-32202
infrastructure 4.3
organisation CVE-2026
general_metric 4.3 score
infrastructure Windows
organisation Microsoft Windows Shell
‎February 22, 2024
Threat actors exploited Actively Exploited ConnectWise and Windows vulnerabilities to target KEV systems.
vulnerability CVE-2024-1709
‎December 2025
Threat actors used a malicious Windows Shortcut (LNK) file to exploit CVE-2024-1709, a critical authentication bypass vulnerability in Windows.
source_region Russian Federation
target_region Ukraine
vulnerability CVE-2026-21510
vulnerability CVE-2026-21513
organisation Akamai
threat_actor APT28
general_metric 21513 CVE-2026
infrastructure Windows
organisation CVE-2026-21510 Exploitation The campaign
organisation Windows Shortcut
organisation CVE-2024-1709
‎January 2026
Threat actors used CVE-2026-21513 to target APT28.
vulnerability CVE-2026-21513
threat_actor APT28
‎February 2026
Threat actors used a vulnerability in ConnectWise and Windows to exploit CVE-2026-21513, allowing them to authenticate to an attacker's server without user interaction.
organisation CVE-2026-21513
general_metric 8.8 latter
infrastructure 8.8
organisation Akamai
tactic Remote Code Execution
organisation SmartScreen
organisation CPL
organisation SMB
‎2026/03/29
Threat actors used CVE-2026-21513 to target ConnectWise systems.
vulnerability CVE-2026-21513
threat_actor APT28
‎April 2026
The incident involved the addition of CVE-2026-32202 to the KEV catalog by CISA, which was followed by Microsoft's update acknowledging that the flaw had been actively exploited.
organisation KEV
organisation Microsoft
‎April 14
Threat actors used a vulnerability in ConnectWise to target Microsoft Windows.
organisation CVSS
‎April 27, 2026
Threat actors used a vulnerability in ConnectWise to target Windows systems.
organisation CVSS
‎Apr 28, 2026
Threat actors used a vulnerability in ConnectWise to target Windows systems.
‎Apr 29, 2026
Threat actors exploited the Actively Exploited ConnectWise vulnerability to target Windows systems.
‎2026/04/29
Microsoft Windows Shell flaw CVE-2026-32202 exploited by APT28.
threat_actor APT28
organisation GruesomeLarch
infrastructure Windows
organisation DLL
organisation UNC
organisation Microsoft
infrastructure 23.9.7
organisation ConnectWise ScreenConnect
organisation CVSS
organisation NTLM
organisation LNK
‎May 12, 2026
Threat actors used a vulnerability in ConnectWise to exploit Windows flaws.
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎4.3
Software Version
Metrics
infrastructure
‎23.9.7
Software Version
Metrics
infrastructure
‎8.8
Software Version