CVE-2024-1709Active Exploitation(connectwise / screenconnect)

MEDIUMCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch connectwise screenconnect systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

5.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-02-29. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-288

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • screenconnect

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 24 mentions across 12 observed days

What's happening

  • Active exploitation reported across 10 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 11 signals
  • Disclosure: 6 classified signals
  • General: 5 classified signals
  • Peaked 9d ago at 9 mentions (2026-04-29); latest day: 1
  • 24 total mentions across 12 days

Affected systems

Products
screenconnect

Deep dive

Activity timeline24 mentions / 12d
02579Mentions · 2026-03-20: 2Mentions · 2026-04-25: 1Mentions · 2026-04-29: 9Mentions · 2026-04-30: 1Mentions · 2026-05-03: 2Mentions · 2026-06-01: 2Mentions · 2026-06-24: 1Mentions · 2026-07-06: 2Mentions · 2026-08-18: 1Mentions · 2026-09-20: 1Mentions · 2026-09-30: 1Mentions · 2026-10-07: 1PoC Mentioned / Linked · 2026-04-29: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-04-29: 4Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-06-01: 1Active Exploitation · 2026-07-06: 2Active Exploitation · 2026-08-18: 1Patch / Workaround · 2026-04-29: 2Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-03-20: 1Technical Details · 2026-04-29: 7Technical Details · 2026-05-03: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-24: 103-2004-2504-2904-3005-0306-0106-2407-0608-1809-2009-3010-07
Signal classification4 categories
Active Exploitation
1045.5%
Disclosure
627.3%
General
522.7%
False Positive
14.5%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-03-202
Active Exploitation1General1
2026-04-251
General1
2026-04-299
Active Exploitation4Disclosure4General1
2026-04-301
Active Exploitation1
2026-05-032
Disclosure1General1
2026-06-012
Active Exploitation1General1
2026-06-241
Disclosure1
2026-07-062
Active Exploitation2
2026-08-181
Active Exploitation1
2026-09-201
False Positive1
Full discourse20 posts
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/28追加) 🛡️No.1585 CVE-2024-1708 ConnectWise ScreenConnect Path Traversal Vulnerability ==================================== ✅概要 ・深刻度:重要 8.4 (CVSS Base) / Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H ConnectWise ScreenConnect 23.9.7 以前に存在するパス・トラバーサルの脆弱性。特権を持つ攻撃者により、リモートコードの実行や機密データ・重要システムへ直接影響を与える恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・self-hosted / on-premise の ConnectWise ScreenConnect 23.9.7 以前が稼働していること。 ・攻撃者が管理者権限を有し、Extensions 機能を利用できること。 ・細工された ZIP 形式の拡張ファイルをアップロードできること。 ✅悪用時影響 ・制限されたディレクトリ外へファイルを書き込まれる ・App_Extensions 配下の想定外の場所へ ASPX / ASHX などのファイルを配置され、リモートからコード実行 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Huntress は公開直後に active exploitation in the wild を確認したとし、Microsoft も Storm-1175 が CVE-2024-1709 と CVE-2024-1708 を悪用対象に含めていたと報告 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-1708 https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8 🛡️No.1586 CVE-2026-32202 Microsoft Windows Protection Mechanism Failure Vulnerability ==================================== ✅概要 ・深刻度:注意 4.3 (CVSS Base) / Microsoft Corporation ・種別:保護メカニズムの不具合 (CWE-693) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N Windows Shell における保護機構の不備により、事前認証されていない攻撃者がネットワーク経由でスプーフィングを実行する恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Windows 10、Windows 11、Windows Server のバージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要、かつ利用者の関与が必要。 ✅悪用時影響 ・ネットワーク経由でスプーフィングを実行される ・利用者を欺いて機微情報へアクセスされる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Microsoft は本脆弱性が実際に悪用されていると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-32202 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202 https://www.cisa.gov/news-events/alerts/2026/04/28/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added CVE-2024-1708 and CVE-2026-32202 to its known exploited vulnerabilities catalog, citing confirmed active exploitation and providing vendor advisory links.

    0001135.0K
    43.6K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 أضافت CISA ثغرتين إلى كتالوج KEV أضافت CISA ثغرتين إلى كتالوج الثغرات المعروفة المستغلة (KEV) وهما CVE-2024-1708 و CVE-2024-1709، بسبب وجود أدلة على استغلالهم بشكل فعال. الثغرة CVE-2024-1708 هي ثغرة تعرض المسار في ConnectWise ScreenConnect. يُنصح بضرورة تطبيق التصحيحات الأمنية اللازمة لتجنب الاستغلال. 🔗 للمزيد: https://thecyberthrone.in/2026/04/29/cisa-adds-two-vulnerabilities-to-kev-catalog-2/

    Post summary

    CISA added CVE‑2024‑1708 and CVE‑2024‑1709 to its KEV catalog due to proven active exploitation, and urges users to apply patches.

    00040800
    267 followersView on X
  • Jason Ferguson@F3RGZILLA

    Hey @AnthropicAI I know it's hard out there right now, but what does it take to get a legitimate platform account unsuspended? You may know me from such hits such as CVE-2026-84869, CVE-2024-1708, or CVE-2024-1709, among many others. @OpenAI do you have space for me?

    2001043
    10 followersView on X
  • GoCocoaAI@GoCocoaAI
    Disclosure

    Sources for the three publicly verified CVEs in this brief: CVE-2024-3094 (XZ Utils / liblzma supply-chain backdoor, CVSS 10.0): https://nvd.nist.gov/vuln/detail/CVE-2024-3094 CVE-2024-1709 (ConnectWise ScreenConnect auth bypass, CVSS 10.0): https://nvd.nist.gov/vuln/detail/CVE-2024-1709 CVE-2024-27198 (JetBrains TeamCity auth bypass, CVSS 9.8): https://nvd.nist.gov/vuln/detail/CVE-2024-27198 Exploitation forecast data, HMM lifecycle posteriors, and aggregate panel signal via AEGIS at 23:46 UTC 2026-06-24. CVE-2024-21413 and CVE-2024-23897 NVD entries available at http://nvd.nist.gov; omitted from allowed URL set for this brief.

    Post summary

    A concise list of three publicly verified CVEs, including NVD links and CVSS scores, with no PoC, exploit code, or patch details provided.

    0002097
    35 followersView on X
  • Bhavesh Verma@xbhaveshverma

    CVEs Explainer #4 CVE-2024-1709 (ConnectWise ScreenConnect Auth Bypass) A critical authentication bypass affecting ScreenConnect versions 23.9.7 and prior. Attackers with network access to the management interface could create a new administrator-level account on affected devices, leading to full remote code execution. It was exploited in ransomware campaigns and is a classic example of why remote management tools are high-value targets.

    0001072
    104 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    Medusa ransomware has escalated its attacks, compromising over 500 critical infrastructure organizations. Exploiting vulnerabilities like CVE-2024-1709 and CVE-2023-48788, it employs advanced evasion techniques, including disabling EDR systems and misusing RMM tools. Organizations must prioritize timely patching and robust cybersecurity measures to mitigate this growing threat. #MedusaRansomware #Cybersecurity #CriticalInfrastructure #Ransomware #Infosec #DataBreach https://thedailytechfeed.com/medusa-ransomware-intensifies-attacks-on-critical-infrastructure/

    Post summary

    The tweet reports that Medusa ransomware is actively exploiting CVE-2024-1709 and CVE-2023-48788 against critical infrastructure organizations, urging timely patching to mitigate the growing threat.

    00010116
    644 followersView on X
  • GoCocoaAI@GoCocoaAI
    Active Exploitation

    The window closed BLUF: The time between vulnerability disclosure and active exploitation is now measured in days, not sprints. Traditional patch cycles were not built for this. 1. Two days is not a cycle The disclosure-to-KEV gap on CVE-2024-1709 (ConnectWise ScreenConnect, CVSS 10. 0, EPSS 99. 96th percentile) was two days. CVE-2024-27198 (JetBrains TeamCity, CVSS 9. 8) was three days. CVE-2024-3094 (XZ Utils supply chain, CVSS 10. 0) was four days. These are not edge cases — they are the new center of the distribution for anything touching remote access, CI/CD pipelines, or widely-deployed enterprise software. Ransomware affiliation is confirmed on three of the four. EPSS flagged near-certain exploitation before CISA added any of them to KEV. The model is now faster than the catalog. 2. The quiet failure mode CVE-2024-20767 (Adobe ColdFusion, CVSS 7. 4, EPSS 99. 90th percentile) took nine months to land in KEV. That is a different failure — medium severity on paper, easy to defer, exploited anyway. Both the fast entries and the slow ones resolve in the same place: unpatched when it mattered. The BleepingComputer piece is circling a structural point the data confirms: scan-triage-ticket-schedule-patch was designed for a world where the exploitation curve ran weeks. That world is gone. Operator take: If CVE-2024-1709 is in your stack, the questions that matter are already overdue — where is it exposed, who owns the patch, what compensating control is live, and what telemetry would prove nobody touched it during the window. The quiet work now is cheaper than the loud paperwork later.

    Post summary

    The post highlights how CVE‑2024‑1709 and similar high‑impact vulnerabilities are being exploited within days of disclosure, underscoring the inadequacy of traditional patch cycles.

    1000038
    15 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-1709: ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.

    Post summary

    ConnectWise ScreenConnect has an authentication bypass flaw that lets a network‑local attacker create a new administrator account on affected devices.

    1000053
    152 followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    CVE-2024-1708 in ConnectWise ScreenConnect was also added to KEV. Storm-1175, a China nexus actor, chains it with CVE-2024-1709 to deliver Medusa ransomware. Healthcare and managed service providers are the confirmed target profile.

    Post summary

    CVE-2024-1708 and CVE-2024-1709 are actively exploited; a China‑based actor chains the CVEs to deliver Medusa ransomware targeting healthcare and managed service providers.

    1000042
    1 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-1709 is a trust topology vulnerability — the tool designed to provide secure remote access becomes the breach vector. In traditional attack models, compromising ScreenConnect grants access to one organization. In MSP deployments, it cascades to hundreds of…

    Post summary

    The text reports CVE-2024-1709 as a trust topology flaw in ScreenConnect that can lead to cascading breaches in MSP deployments, but it does not mention PoC, exploits, patches, or active exploitation.

    1000027
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-1709 is a perfect-score authentication bypass in ConnectWise ScreenConnect, a remote access platform deployed across 1+ million organizations globally. The vulnerability allows unauthenticated attackers to gain full administrative access by sending a single HTTP…

    Post summary

    The text announces CVE‑2024‑1709 as a perfect‑score authentication bypass in ConnectWise ScreenConnect, but it offers no PoC, exploit code, active exploitation evidence, patch info, or false‑positive claim.

    1000027
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-1709: CVE-2024-1709: ConnectWise ScreenConnect Supply Chain Breach Vector... (10.0 → 23.9.7)

    Post summary

    The post announces CVE-2024-1709 as a supply‑chain breach vector for ConnectWise ScreenConnect, affecting versions 10.0 through 23.9.7, with limited technical detail provided.

    1000024
    125 followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam
    False Positive

    @soulsimplifai connectwise tag plus AWS ASN screams CVE-2024-1709 leftovers, not fresh compromise. urlhaus online/offline is polled, not live, AS16509 ips recycle fast. false positive rate on that status field?

    Post summary

    The tweet argues that CVE-2024-1709 detections tied to ConnectWise Tag Plus and AWS ASN (AS16509) are stale artifacts rather than fresh compromises, questioning the reliability of URLHaus polling data and highlighting likely false positives in the status indicators.

    00000125
    1.3K followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2024-1709 — Akamai Connected Cloud Visit -- https://cti.loginsoft.com/ip/172.105.191.25 #Loginsoft #Cytellite #Cybersecurity #CVE20241709 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/WiSor9HO4x

    Post summary

    The tweet reports recent detection of live exploitation targeting CVE-2024-1709.

    0000049
    22 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2024-1709 — Akamai Connected Cloud Visit -- https://cti.loginsoft.com/ip/172.105.191.25 #Loginsoft #Cytellite #Cybersecurity #CVE20241709 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/S9Eb8E7qLb

    Post summary

    Cytellite notes recent detection of activity targeting CVE-2024-1709 on Akamai Connected Cloud, indicating potential active exploitation, but the tweet lacks a PoC, exploit details, patch information, or deep technical context.

    0000045
    22 followersView on X
  • GoCocoaAI@GoCocoaAI
    General

    Source trail for the operator desk. BleepingComputer on why alert speed is the new constraint: https://www.bleepingcomputer.com/news/security/race-against-time-why-faster-vulnerability-alerts-matter/ — CVE-2024-1709 NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2024-1709 https://t.co/OfH3tJp0hp

    Post summary

    The tweet links to a BleepingComputer article about faster vulnerability alerts and mentions CVE‑2024‑1709, but provides no detailed technical, exploitation, or mitigation information.

    0000031
    15 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/active-exploit-cve-2024-1709-screenconnect #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided snippet mentions a CVE via a link and hashtags but offers no concrete technical or contextual details.

    0000031
    152 followersView on X
  • Dr.Mashari@GMashari
    Active Exploitation

    📌 أضافت CISA ثغرتين إلى كتالوج KEV بسبب استغلالهما بشكل فعال 🛡️ الفئة: ثغرة 📝 الملخص: أضافت CISA ثغرتين إلى كتالوج الثغرات المعروفة المستغلة (KEV) وهما CVE-2024-1708 و CVE-2024-1709، بسبب وجود أدلة على استغلالهم بشكل فعال. الثغرة CVE-2024-1708 هي ثغرة تعرض المسار في ConnectWise ScreenConnect. يُنصح بضرورة تطبيق التصحيحات الأمنية اللازمة لتجنب الاستغلال. 🗓️ تاريخ النشر: 29/04/2026 🔗 للمزيد: https://thecyberthrone.in/2026/04/29/cisa-adds-two-vulnerabilities-to-kev-catalog-2/

    Post summary

    CISA added CVE‑2024‑1708 and CVE‑2024‑1709 to the KEV catalog because of proven active exploitation, and urges users to apply security patches for ConnectWise ScreenConnect.

    0000044
    8.9K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    BREAKING: CISA adds actively exploited ScreenConnect flaws CVE-2024-1708 and CVE-2024-1709 to KEV catalog, confirming ongoing attacks via SlashAndGrab exploit chain. https://threatcluster.io/cluster/critical-vulnerabilities-in-connectwise-screenconnect-exploi-a6b8c45f

    Post summary

    CISA confirms CVE-2024-1708 and CVE-2024-1709 are actively exploited in the wild via the SlashAndGrab chain, adding them to the KEV catalog.

    0000047
    166 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/cve-2024-1709-connectwise-screenconnect-supply-chain-breach #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text only cites a research link and hashtags, with no explicit information on exploit, patch, or technical details about CVE-2024-1709.

    0000025
    125 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appconnectwisescreenconnect---

Explore more