logo

Critical Vulnerabilities in ConnectWise ScreenConnect Patched

ID: 00c09cee-81c9-52d8-93b4-9625f16d0ad0

STIX ID: report--00c09cee-81c9-52d8-93b4-9625f16d0ad0

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2024-02-20

Date Updated: 2026-07-25

Author: Andres Ramos

...
...

On February 19, 2024 ConnectWise published an advisory for two critical vulnerabilities in on‑premises ScreenConnect (an authentication bypass rated CVSS 10 and a path traversal rated CVSS 8.4) that could lead to remote code execution; cloud-hosted ScreenConnect instances have been patched and on‑premises users should upgrade to 23.9.8 immediately. Arctic Wolf warns threat actors are likely to target these severe, low-complexity flaws given ScreenConnect's historical abuse, but reports no observed exploitation or public PoCs at this time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.