logo

Security alert: ConnectWise ScreenConnect 23.9.8 security fix

ID: a3964b16-fe9c-5bca-9519-b493bc7bad26

STIX ID: report--a3964b16-fe9c-5bca-9519-b493bc7bad26

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2024-02-20

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

ConnectWise disclosed a critical authentication-bypass and path-traversal vulnerability in self-hosted/on-premise ScreenConnect (<=23.9.7) rated CVSS 10, actively exploited in the wild; customers must immediately upgrade to ScreenConnect server 23.9.8 (cloud instances already patched by ConnectWise).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.