Description
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
CISA Known Exploited Vulnerability
Date added 2026-04-28 | Due date 2026-05-12
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version
References
www.microsoft.com/...igh-tempo-medusa-ransomware-operations/
www.cisa.gov/...nerabilities-catalog?field_cve=CVE-2024-1708
www.connectwise.com/...tins/connectwise-screenconnect-23.9.8
www.huntress.com/...-the-screenconnect-authentication-bypass
www.connectwise.com/...tins/connectwise-screenconnect-23.9.8
www.huntress.com/...-the-screenconnect-authentication-bypass