CVE-2024-1708Active Exploitation(connectwise / screenconnect)

MEDIUMCVSS 8.4 · HIGHCISA KEV

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch connectwise screenconnect systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

5.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • screenconnect

Threat summary

  • Active exploitation appears in 25 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 39 mentions across 12 observed days

What's happening

  • Active exploitation reported across 25 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 28 signals
  • Disclosure: 3 classified signals
  • Peaked 10d ago at 15 mentions (2026-04-29); latest day: 1
  • 39 total mentions across 12 days

Affected systems

Products
screenconnect

Deep dive

Activity timeline39 mentions / 12d
0481115Mentions · 2026-04-28: 1Mentions · 2026-04-29: 15Mentions · 2026-04-30: 6Mentions · 2026-05-01: 3Mentions · 2026-05-02: 3Mentions · 2026-05-04: 2Mentions · 2026-05-05: 1Mentions · 2026-05-06: 2Mentions · 2026-05-07: 3Mentions · 2026-05-12: 1Mentions · 2026-08-24: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-04-29: 1PoC Mentioned / Linked · 2026-05-02: 1PoC Mentioned / Linked · 2026-08-24: 1Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-04-29: 14Active Exploitation · 2026-04-30: 6Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-02: 2Active Exploitation · 2026-05-04: 1Patch / Workaround · 2026-04-29: 7Patch / Workaround · 2026-04-30: 3Patch / Workaround · 2026-05-01: 3Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 2Patch / Workaround · 2026-05-07: 2Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 12Technical Details · 2026-04-30: 2Technical Details · 2026-05-01: 1Technical Details · 2026-05-02: 3Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 3Technical Details · 2026-05-12: 1Technical Details · 2026-08-24: 104-2804-2904-3005-0105-0205-0405-0505-0605-0705-1208-2409-30
Signal classification4 categories
Active Exploitation
2565.8%
Patch
923.7%
Disclosure
37.9%
General
12.6%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-04-281
Active Exploitation1
2026-04-2915
Active Exploitation14Patch1
2026-04-306
Active Exploitation6
2026-05-013
Active Exploitation1Patch2
2026-05-023
Active Exploitation2Disclosure1
2026-05-042
Active Exploitation1Patch1
2026-05-051
Patch1
2026-05-062
Patch2
2026-05-073
Disclosure1Patch2
2026-05-121
General1
2026-08-241
Disclosure1
Full discourse20 posts
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added ConnectWise ScreenConnect path traversal vulnerability CVE-2024-1708 & Microsoft Windows protection mechanism failure vulnerability CVE-2026-32202 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity https://t.co/dQcNvxcejN

    Post summary

    The DHS announcement adds CVE‑2024‑1708 and CVE‑2026‑32202 to its Known Exploited Vulnerabilities Catalog, indicating these flaws are being actively exploited, but no PoC, exploit code, or patch information is provided.

    41704397.6K
    299.5K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/28追加) 🛡️No.1585 CVE-2024-1708 ConnectWise ScreenConnect Path Traversal Vulnerability ==================================== ✅概要 ・深刻度:重要 8.4 (CVSS Base) / Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H ConnectWise ScreenConnect 23.9.7 以前に存在するパス・トラバーサルの脆弱性。特権を持つ攻撃者により、リモートコードの実行や機密データ・重要システムへ直接影響を与える恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・self-hosted / on-premise の ConnectWise ScreenConnect 23.9.7 以前が稼働していること。 ・攻撃者が管理者権限を有し、Extensions 機能を利用できること。 ・細工された ZIP 形式の拡張ファイルをアップロードできること。 ✅悪用時影響 ・制限されたディレクトリ外へファイルを書き込まれる ・App_Extensions 配下の想定外の場所へ ASPX / ASHX などのファイルを配置され、リモートからコード実行 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Huntress は公開直後に active exploitation in the wild を確認したとし、Microsoft も Storm-1175 が CVE-2024-1709 と CVE-2024-1708 を悪用対象に含めていたと報告 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-1708 https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 🛡️No.1586 CVE-2026-32202 Microsoft Windows Protection Mechanism Failure Vulnerability ==================================== ✅概要 ・深刻度:注意 4.3 (CVSS Base) / Microsoft Corporation ・種別:保護メカニズムの不具合 (CWE-693) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N Windows Shell における保護機構の不備により、事前認証されていない攻撃者がネットワーク経由でスプーフィングを実行する恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Windows 10、Windows 11、Windows Server のバージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要、かつ利用者の関与が必要。 ✅悪用時影響 ・ネットワーク経由でスプーフィングを実行される ・利用者を欺いて機微情報へアクセスされる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Microsoft は本脆弱性が実際に悪用されていると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-32202 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202 https://www.cisa.gov/news-events/alerts/2026/04/28/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirms that CVE‑2024‑1708 and CVE‑2026‑32202 are actively exploited in the wild, with detailed technical information and vendor patches referenced.

    0001135.0K
    43.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2024-1708 - high 🚨 ConnectWise ScreenConnect <= 23.9.7 - Path Traversal > ConnectWise ScreenConnect 23.9.7 and prior contain a path traversal caused by imprope... 👾 https://cloud.projectdiscovery.io/library/CVE-2024-1708 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2024-1708 is a high‑severity path traversal flaw affecting ConnectWise ScreenConnect 23.9.7 and earlier, with a link to additional details provided.

    00032288
    1.3K followersView on X
  • CyHawk Africa@CyhawkAfrica
    Active Exploitation

    🚨 CISA KEV ALERT: SCREENCONNECT 🚨 CISA just flagged an actively exploited, high-severity vulnerability in ConnectWise ScreenConnect. Priority Action Items: Vulnerability: CVE-2024-1708 (CVSS Score: 8.4) Flaw: Path Traversal Impact: This vulnerability allows an attacker to execute remote code or directly impact confidential data and critical systems. #CyberSecurity #ThreatIntel #ConnectWise #InfoSec

    Post summary

    CISA warned that CVE-2024-1708, a path traversal flaw in ConnectWise ScreenConnect with CVSS 8.4, is actively being exploited to gain remote code execution.

    00041152
    123 followersView on X
  • Cyber Recon@KaliSushanth
    Active Exploitation

    🚨 CISA confirms active exploitation of CVE-2024-1708 in ConnectWise ScreenConnect. Path traversal → remote code execution → full network takeover. Ransomware groups are already on this. Patch by May 12 or isolate NOW. This isn't just a US problem. #CyberSecurity #InfoSec

    Post summary

    CISA confirms active exploitation of CVE-2024-1708 in ConnectWise ScreenConnect, enabling path traversal that leads to remote code execution and potential network takeover, and urges patching by May 12.

    11020102
    2 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 أضافت CISA ثغرتين إلى كتالوج KEV أضافت CISA ثغرتين إلى كتالوج الثغرات المعروفة المستغلة (KEV) وهما CVE-2024-1708 و CVE-2024-1709، بسبب وجود أدلة على استغلالهم بشكل فعال. الثغرة CVE-2024-1708 هي ثغرة تعرض المسار في ConnectWise ScreenConnect. يُنصح بضرورة تطبيق التصحيحات الأمنية اللازمة لتجنب الاستغلال. 🔗 للمزيد: https://thecyberthrone.in/2026/04/29/cisa-adds-two-vulnerabilities-to-kev-catalog-2/

    Post summary

    CISA added CVE-2024-1708 and CVE-2024-1709 to its KEV catalog due to evidence of active exploitation, urging organizations to apply patches to mitigate the threat.

    00040800
    267 followersView on X
  • Jason Ferguson@F3RGZILLA

    Hey @AnthropicAI I know it's hard out there right now, but what does it take to get a legitimate platform account unsuspended? You may know me from such hits such as CVE-2026-84869, CVE-2024-1708, or CVE-2024-1709, among many others. @OpenAI do you have space for me?

    2001043
    10 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 أضافت CISA ثغرتين يتم استغلالهما بشكل فعال في ConnectWise و Windows إلى قائمة KEV أضافت وكالة الأمن السيبراني وأمن البنية التحتية الأمريكية (CISA) ثغرتين جديدتين إلى قائمة الثغرات المعروفة المستغلة (KEV)، وهما CVE-2024-1708 وCVE-2024-1709 المتعلقتين بـ ConnectWise ScreenConnect و Microsoft Windows. تم استغلال هذه الثغرات بشكل فعال من قبل المهاجمين، مما يستوجب اتخاذ إجراءات فورية لتحديث الأنظمة المتضررة. يُنصح بـ تطبيق التصحيحات الأمنية على الفور. 🔗 للمزيد: https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html

    Post summary

    CISA added CVE-2024-1708 and CVE-2024-1709 to the KEV list due to active exploitation in ConnectWise ScreenConnect and Microsoft Windows, and recommends applying security patches immediately.

    00030873
    267 followersView on X
  • 404🌐LABS@404LABSx
    Patch

    🚨 THREAT INTEL | May 1, 2026 PATCH: CVE-2026-41940 cPanel (due May 3) + CVE-2024-1708 ConnectWise RCE ACTIVE: QakBot C2, Vidar, LummaStealer, 500+ malicious URLs NEW: Needle Stealer + PhantomRPC Windows LPE #CyberSecurity #Infosec https://t.co/kJ4xBBgQTp

    Post summary

    The tweet announces that a patch for CVE-2026-41940 is due on May 3 and references ConnectWise RCE with CVE-2024-1708, but provides no exploit details or PoC.

    00020157
    53 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    CISA KEV 警告 26/04/28:ScreenConnect の脆弱性 CVE-2024-1708 を登録 https://iototsecnews.jp/2026/04/29/cisa-warns-of-connectwise-screenconnect-flaw-exploited-in-attacks/ 脆弱性 CVE-2024-1708 は、プログラムが想定していない場所にあるファイルへのアクセスを許してしまう、パス・トラバーサルに起因します。本来であれば、アプリケーションは特定の安全なフォルダの中だけで動作するべきですが、入力値のチェックが不十分だと、その制限を攻撃者がすり抜けてしまいます。リモート・デスクトップのような強力な権限を持つツールに、この問題が起きると、システムの根幹を揺るがす大きなリスクにつながります。ご利用のチームは、ご注意ください。よろしければ、CISA KEV ページも、ご参照ください。 #CISA #ConnectWise #CVE20241708 #Exploit #KEV #ScreenConnect #Vulnerability

    Post summary

    CISA announced a KEV for CVE‑2024‑1708, identifying a path‑traversal flaw in ScreenConnect that could allow remote attackers to bypass file‑access restrictions, but no active exploitation or patch information was provided.

    01000108
    487 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-1708: ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

    Post summary

    The tweet announces a path traversal vulnerability in ConnectWise ScreenConnect that could enable remote code execution and compromise confidential data.

    1000051
    152 followersView on X
  • Solomon Neas@solomonneas
    Active Exploitation

    Cyber watch: 🔴 Gemini CLI host RCE: patch CLI/action, audit tokens. 🔴 ScreenConnect CVE-2024-1708 in KEV: patch exposed remote-access servers. 🟡 Mini Shai-Hulud hits npm/PyPI/PHP: rotate dev secrets. http://solomonneas.dev/intel

    Post summary

    The post highlights several vulnerabilities, notably ScreenConnect CVE-2024-1708 as a KEV (actively exploited) and advises patching; it also mentions Gemini CLI host RCE and Shai‑Hulud abuse but offers no PoC or exploitation code.

    0001078
    88 followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    CVE-2024-1708 in ConnectWise ScreenConnect was also added to KEV. Storm-1175, a China nexus actor, chains it with CVE-2024-1709 to deliver Medusa ransomware. Healthcare and managed service providers are the confirmed target profile.

    Post summary

    CVE‑2024‑1708 in ConnectWise ScreenConnect has been added to the KEV roster and is actively being exploited by the China‑based Storm‑1175 actor, who chains it with CVE‑2024‑1709 to deliver Medusa ransomware to healthcare and managed‑service providers.

    1000042
    1 followersView on X
  • AI Security Gateway@AISGateway
    Active Exploitation

    🚨CISA just added actively exploited ConnectWise & Windows flaws to its KEV catalog. CVE-2024-1708 scores 8.4 CVSS. But here's what the AI security world should take from this: your LLM infrastructure has the same exposure surface as any other networked system.

    Post summary

    CISA has listed CVE‑2024‑1708, an 8.4‑scored flaw, as actively exploited in the wild, emphasizing that LLM infrastructures share the same exposure surface as any other networked system.

    1000050
    31 followersView on X
  • 404🌐LABS@404LABSx
    General

    🚨 THREAT INTEL | May 12, 2026 🔴 CVEs DUE TODAY: CVE-2024-1708 (ConnectWise RCE), CVE-2026-32202 (Windows) 🔥 OVERDUE: PAN-OS RCE, Cisco FMC Ransomware RCE 🐛 LIVE: Mirai/Mozi botnets + Manji malware 🔐 NEW C&C: Vidar, AsyncRAT, PureHVNC #ThreatIntel #CyberSecurity #PatchNow https://t.co/OgC9gWdgby

    Post summary

    The post alerts about two CVEs due today, providing basic technical details but lacking exploit code, active exploitation evidence, or patch guidance.

    00000142
    54 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A path traversal vulnerability (CVE-2024-1708) affects ConnectWise ScreenConnect. Apply vendor mitigations soon or consider discontinuing use if unavailable. Stay proactive to protect your IT environment. #Cybersecurity

    Post summary

    The message alerts that CVE‑2024‑1708, a path traversal flaw in ConnectWise ScreenConnect, requires vendor mitigations, urging users to apply patches promptly.

    0000043
    74 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A known path traversal vulnerability in ConnectWise ScreenConnect (CVE-2024-1708) requires timely action. Businesses using this tool should apply vendor mitigations or consider alternatives before the May 2026 deadline to maintain security hygiene. #Cybersecurity

    Post summary

    The post warns of a path traversal flaw in ConnectWise ScreenConnect (CVE‑2024‑1708) and urges users to apply vendor mitigations before a May 2026 deadline.

    0000054
    72 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    The ConnectWise ScreenConnect vulnerability (CVE-2024-1708) requires action by May 2026. Review vendor guidance, apply necessary mitigations, or consider alternatives if unavailable. Stay proactive to protect your IT environment. #Cybersecurity

    Post summary

    The message highlights the impending action deadline for CVE‑2024‑1708 and recommends following vendor guidance and applying mitigations before May 2026.

    0000038
    72 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    The ConnectWise ScreenConnect Path Traversal vulnerability (CVE-2024-1708) highlights the importance of promptly applying vendor-recommended mitigations or considering alternative solutions to maintain your cybersecurity hygiene. #Cybersecurity

    Post summary

    The post cautions users to apply vendor recommended mitigations for CVE‑2024‑1708, a Path Traversal flaw.

    0000045
    72 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2024-1708 affects ConnectWise ScreenConnect with a path traversal vulnerability. Small and mid-sized businesses should follow vendor mitigation steps or consider alternatives before the 2026-05-12 deadline to maintain strong security posture. #Cybersecurity

    Post summary

    CVE‑2024‑1708 is a path traversal flaw in ConnectWise ScreenConnect; users are urged to apply vendor mitigation steps before the deadline.

    0000040
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appconnectwisescreenconnect---

Explore more