CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability

High severity, CVSS 8.4. Actively exploited: in CISA KEV since 2026-04-28. EPSS: 95.4% chance of exploitation in the next 30 days.

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

Affected products

  • ConnectWise ScreenConnect: before 23.9.8 (fixed in 23.9.8)

Published 2024-02-21. Last modified 2026-06-17.