logo

CISA Warns of ConnectWise ScreenConnect Flaw Exploited in Attacks

ID: c06dcd33-a0b6-5230-91cb-8456e91df243

STIX ID: report--c06dcd33-a0b6-5230-91cb-8456e91df243

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Divya

...
...

CISA warns that CVE-2024-1708, a path traversal vulnerability in ConnectWise ScreenConnect, is being actively exploited and was added to the Known Exploited Vulnerabilities catalog; federal agencies must patch by May 12, 2026 under BOD 22-01. The flaw can allow attackers to read/write files outside intended directories and potentially achieve full system takeover, so immediate patching, configuration reviews, monitoring, and removal of the product if unpatchable are strongly recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.