CVE-2024-1709

CRITICAL10.0Published on February 21, 2024

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Feb 22, 2024
  • US federal agencies must remediate it by Feb 29, 2024 (BOD 22-01)
  • Attacked 2 days before the vulnerability was made public
  • Confirmed by sensors, not only by reports
  • Used in ransomware campaigns

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Aug 20, 2026 Aug 19, 2026 Aug 18, 2026 Aug 17, 2026 Aug 16, 2026 Aug 15, 2026

CVSS score10.0 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness type (CWE)CWE-288
Vendorsconnectwise

Affected products

VendorsProdottoVersioni
connectwisescreenconnect< 23.9.8

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database