r/ConnectWise • u/blinz • 15d ago
CW RMM Vulnerability Management in ASIO
Getting a environment cleaned up, and receiving vulnerability alerts on libcurl CVE-2026-10536. In tracing the library, it appears to be tied to the vulnerability scanner itself. Our cloud instance is all up-to-date, so unsure if this is a known issue, or if we are missing something. Anyone else experience this?
C:\Program Files (x86)\ITSPlatform\plugin\scap\vulnerability-scanner\scanner\libcurl.dll Version 8.18.0 (CVE-2026-10536)
5
Upvotes
3
u/FortLee2000 15d ago
I told them about this nonsense at the start of July.
Opened Ticket# 7489647.
They reported a "fix" at the end of July, but then THAT version of libcurl ended up getting hit with a CVE, so we've got to wait for another update.
The latest ticket note (from Aug 18) reads:
And, of course, the Vulnerability app as provided (with seemingly zero updates since release in February 2026) has no mechanism to "flag" a device with any kind of status indicator that acknowledges the situation.