CISA Warns of ConnectWise ScreenConnect Flaw Exploited in Attacks
ID: c06dcd33-a0b6-5230-91cb-8456e91df243
STIX ID: report--c06dcd33-a0b6-5230-91cb-8456e91df243
Feed Name: GBHackers
CISA warns that CVE-2024-1708, a path traversal vulnerability in ConnectWise ScreenConnect, is being actively exploited and was added to the Known Exploited Vulnerabilities catalog; federal agencies must patch by May 12, 2026 under BOD 22-01. The flaw can allow attackers to read/write files outside intended directories and potentially achieve full system takeover, so immediate patching, configuration reviews, monitoring, and removal of the product if unpatchable are strongly recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
