CVE-2024-1709
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Feb 22, 2024
- US federal agencies must remediate it by Feb 29, 2024 (BOD 22-01)
- Attacked 2 days before the vulnerability was made public
- Confirmed by sensors, not only by reports
- Used in ransomware campaigns
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Aug 20, 2026 Aug 19, 2026 Aug 18, 2026 Aug 17, 2026 Aug 16, 2026 Aug 15, 2026
CVSS score10.0 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeakness type (CWE)CWE-288
Vendorsconnectwise
Affected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| connectwise | screenconnect | < 23.9.8 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
