ConnectWise Patches High-Severity XSS and Session Cookie Vulnerabilities in PSA Platform

Share
ConnectWise Patches High-Severity XSS and Session Cookie Vulnerabilities in PSA Platform

ConnectWise has released a security update for its Professional Services Automation (PSA) platform, addressing two vulnerabilities that could allow stored script execution and session cookie theft.

The company recommends upgrading to version 2026.1 as soon as possible.

Vulnerabilities

CVE IDTypeCVSS ScoreImpact
CVE-2026-0695Cross-Site Scripting (XSS)8.7 (High)Stored script execution
CVE-2026-0696Sensitive Cookie Without HttpOnly6.5 (Medium)Session cookie exposure

CVE-2026-0695 - Stored XSS

A flaw in Time Entry note handling could permit stored script execution in both the PSA web client and PSA Desktop application. Successful exploitation could lead to:

  • Session hijacking
  • Actions performed on behalf of authenticated users
  • Access to sensitive data

CVE-2026-0696 - Cookie Exposure

A separate condition could allow client-side access to certain session cookies due to missing HttpOnly flags. This could enable attackers to steal session tokens via JavaScript.

Affected Versions

All ConnectWise PSA versions prior to 2026.1.

Remediation

  • Cloud: Instances are being automatically updated
  • On-premise: Apply the 2026.1 release patches and ensure all desktop clients are updated

ConnectWise has assigned this a Priority 2 (Moderate) rating, recommending installation "as soon as possible (e.g. within days)."

Why This Matters

ConnectWise PSA is widely used by managed service providers (MSPs) and IT service companies. MSP tools are frequent targets for attackers seeking to compromise multiple downstream clients through a single breach point.

Read more

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

A compromised version of the Nx Console extension — a popular VS Code plugin with over 2.2 million installations — was published to the Visual Studio Code Marketplace after an attacker leveraged stolen developer credentials to inject a multi-stage credential stealer into the official nrwl/nx GitHub repository. The malicious version

By Zero Day Wire
Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Symantec and Carbon Black have published a definitive analysis confirming that Fast16, a Lua-based malware framework first surfaced by SentinelOne weeks ago, was purpose-built to sabotage nuclear weapons testing simulations. The findings establish Fast16 as the earliest known cyber sabotage tool targeting nuclear weapons research — predating the first known version

By Zero Day Wire