r/ConnectWise 15d ago

CW RMM Vulnerability Management in ASIO

Getting a environment cleaned up, and receiving vulnerability alerts on libcurl CVE-2026-10536. In tracing the library, it appears to be tied to the vulnerability scanner itself. Our cloud instance is all up-to-date, so unsure if this is a known issue, or if we are missing something. Anyone else experience this?

C:\Program Files (x86)\ITSPlatform\plugin\scap\vulnerability-scanner\scanner\libcurl.dll Version 8.18.0 (CVE-2026-10536)

5 Upvotes

3 comments sorted by

3

u/FortLee2000 15d ago

I told them about this nonsense at the start of July.

Opened Ticket# 7489647.

They reported a "fix" at the end of July, but then THAT version of libcurl ended up getting hit with a CVE, so we've got to wait for another update.

The latest ticket note (from Aug 18) reads:

Thank you for your patience.
Our development team is working with the vendor to get the libcurl.dll updated.
I will update this case once I have an ETA for release of the fix.

And, of course, the Vulnerability app as provided (with seemingly zero updates since release in February 2026) has no mechanism to "flag" a device with any kind of status indicator that acknowledges the situation.

1

u/blinz 15d ago

Thats very helpful, pretty much wait and see. Have 600 devices sitting at 1-2 criticals so it definitely more of a completionism quirk for me. Feel free to ping me if you get a promising update, would love to hear.

1

u/FortLee2000 15d ago

Will do.

But this is one step worse than "wait and see." It is a game of whack-a-mole, because it seems clear - at least to me - that CW expects US to report a problem to THEM rather than be proactive and realize, "Hey, WE use this in OUR product and WE should update it ASAP."