Critical ConnectWise RMM Bug Poised for Exploitation Avalanche
ID: f18d07eb-0ab0-5aa5-b906-0b9f4dfe6da6
STIX ID: report--f18d07eb-0ab0-5aa5-b906-0b9f4dfe6da6
Feed Name: Dark Reading
Date Published: 2024-02-21
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
ConnectWise ScreenConnect has a critical authentication bypass (CVSS 10) and a secondary path-traversal flaw that are being actively exploited after public proof-of-concept disclosures; roughly 3,800 self-hosted instances (~93%) remain vulnerable, enabling attackers to create administrative accounts and potentially execute large-scale compromises or supply-chain attacks against MSPs/MSSPs. ConnectWise published advisories and IoCs, and operators are urged to upgrade to version 23.9.8 immediately and hunt for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
