CISA Adds Windows Shell and ConnectWise ScreenConnect Flaws to KEV After Microsoft's April Patch Failed to Mark Zero-Click Bug as Exploited
CISA added CVE-2026-32202 and CVE-2024-1708 to the Known Exploited Vulnerabilities catalog on April 28, giving federal agencies until May 12 to patch a zero-click NTLM coercion flaw whose Patch Tuesday entry carried no exploitation marker.
5 min read3 sources