logo

Update now! ConnectWise ScreenConnect vulnerability needs your attention

ID: 455a4f30-5ea9-54db-a27b-bc0b5dfbda60

STIX ID: report--455a4f30-5ea9-54db-a27b-bc0b5dfbda60

Feed Name: Malwarebytes Blog

Threat Score
90/100

Date Published: 2024-02-23

Date Updated: 2026-04-28

...
...

ConnectWise ScreenConnect has a critical authentication-bypass vulnerability (CVE-2024-1709, CVSS 10) actively exploited in the wild; Shadowserver found ~3,800 vulnerable on-prem instances, CISA added it to its Known Exploited Vulnerabilities catalog, and ConnectWise shared three IPs attributed to attackers. Self-hosted/on-prem partners must update to ScreenConnect 23.9.8 immediately to remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.