CVE-2024-1709: ConnectWise ScreenConnect Authentication Bypass Vulnerability

Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2024-02-22. EPSS: 100% chance of exploitation in the next 30 days.

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

Affected products

  • ConnectWise ScreenConnect: before 23.9.8 (fixed in 23.9.8)

Published 2024-02-21. Last modified 2026-06-17.