logo

Critical Authentication Bypass Vulnerability in ScreenConnect (CVE-2024-1709) | UpGuard

ID: e1a13cab-b03b-5c1a-9095-02bbb284bcaf

STIX ID: report--e1a13cab-b03b-5c1a-9095-02bbb284bcaf

Feed Name: UpGuard Blog

Threat Score
85/100

Date Published: 2024-02-28

Date Updated: 2026-05-01

...
...

ConnectWise disclosed critical vulnerabilities in on-premises ScreenConnect (CVE-2024-1709 — CVSS 10.0 — and CVE-2024-1708 — CVSS 8.4) that can be chained to bypass authentication and achieve remote code execution; multiple PoCs and reported malicious IPs exist, CISA has cataloged the KEV, and organizations are urged to update to the fixed ScreenConnect version and investigate potential compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.