U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

2026-04-29T08:51:46Za3ace7ec1e9167d829a9b0a1f302be2be587979752362e2888ee0e9022bcca41
Agent ID AdministratorAndroid spywareAnodotBrowserGateCISA KEVConnectWise ScreenConnectGitHubLinkedInMedtronicMicrosoft Entra IDMorpheusNCSCRCEShinyHuntersSilentGlassVimeoWindows Shelldata-breachespionageknown-exploited-vulnerabilitiesphishingprivilege-escalationremote-code-executionspear-phishing

What happened

Feed covers multiple high-impact security events: CISA added Microsoft Windows Shell and ConnectWise ScreenConnect vulnerabilities (including CVE-2024-02-21 path traversal) to its Known Exploited Vulnerabilities catalog. A critical GitHub remote code execution flaw (CVE-2026-3854) was disclosed that can be exploited with a single git push. Threat actors (ShinyHunters) exploited an Anodot breach to access Vimeo metadata and reportedly claimed a separate Medtronic incident affecting millions of records. Microsoft patched a Microsoft Entra ID privilege-escalation weakness involving the Agent ID •

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
a3ace7ec1e9167d829a9b0a1f302be2be587979752362e2888ee0e9022bcca41
Enrichment time
2026-04-29T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.