CISA's list that day
28 April 2026
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in ConnectWise ScreenConnect and Microsoft Windows. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2024-1708Path Traversal | ConnectWise ScreenConnect | Patch nowRansomware use, listed within a year; Metasploit module | 0.95 | ||
| CVE-2026-32202Protection Mechanism Failure | Microsoft Windows | Patch soon | 0.05 |