logo

Critical Vulnerabilities in ConnectWise ScreenConnect Patched

ID: 8419bc1e-051f-5a8f-9feb-e08696605818

STIX ID: report--8419bc1e-051f-5a8f-9feb-e08696605818

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2024-02-20

Date Updated: 2026-04-27

...
...

On February 19, 2024 ConnectWise published a bulletin for on‑premises ScreenConnect addressing two critical vulnerabilities — an authentication-bypass that can lead to remote code execution (CVSS 10) and a path traversal issue (CVSS 8.4). Cloud-hosted ScreenConnect instances have been updated; organizations running on-premises ScreenConnect 23.9.7 or earlier are advised to immediately upgrade to 23.9.8. Arctic Wolf warns threat actors are highly likely to target these severe, low-complexity flaws given ScreenConnect’s historical misuse, though no active exploitation or PoC had been observed at the time of the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.