ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8
https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation/
https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive/
https://www.hipaajournal.com/medusa-ransomware/
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html
https://thehackernews.com/2026/04/china-linked-storm-1175-exploits-zero.html
https://www.infosecurity-magazine.com/news/microsoft-critical-goanywhere/
https://securelist.com/vulnerabilities-and-exploits-in-q2-2025/117333/
https://thehackernews.com/2025/05/connectwise-hit-by-cyberattack-nation.html
https://www.theregister.com/2025/03/13/medusa_ransomware_infects_300_critical/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
https://securelist.com/vulnerabilities-and-exploits-in-q4-2024/115761/
https://hackread.com/microsoft-badpilot-campaign-seashell-blizzard-usa-uk/
https://www.theregister.com/2025/02/12/russias_sandworm_caught_stealing_credentials/
https://therecord.media/sandworm-subgroup-russia-europe
https://thehackernews.com/2025/02/microsoft-uncovers-sandworm-subgroups.html
https://securelist.com/vulnerability-exploit-report-q2-2024/113455/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a
https://securelist.com/vulnerability-report-q1-2024/112554/
https://veriti.ai/blog/vulnerable-villain-when-hackers-get-hacked/
https://www.mandiant.com/resources/blog/initial-access-brokers-exploit-f5-screenconnect
https://thehackernews.com/2024/03/china-linked-group-breaches-networks.html
https://www.mandiant.com/resources/blog/connectwise-screenconnect-hardening-remediation
https://github.com/chengbochuan3/CVE-Enterprise-Software
https://github.com/razureink/cve-2024-1708-connectwise_rce_reproduction
https://github.com/godly-raam/CVE-Research-Portfolio
https://github.com/ykrishhh/cve-pocs
https://github.com/nikjohn7/VulnPulse
https://github.com/Teexo/ScreenConnect-CVE-2024-1709-Exploit
https://github.com/JoshuaOrtizR/Proof-Of-Concepts
https://github.com/AMRICHASFUCK/Mass-CVE-2024-1709
https://github.com/AhmedMansour93/Event-ID-229-Rule-Name-SOC262-CVE-2024-1709-
https://github.com/ShadowByte1/CVES
https://github.com/Pr0t0c01/CVEs
https://github.com/tr1pl3ight/CVE-2024-21762-POC
https://github.com/tr1pl3ight/POCv2.0-for-CVE-2024-1709
https://github.com/HussainFathy/CVE-2024-1709
https://github.com/W01fh4cker/ScreenConnect-AuthBypass-RCE
https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2
https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1709
https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc
Published: 2024-02-21
Updated: 2026-02-26
Named Vulnerability: SlashAndGrabKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 10
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
Base Score: 10
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Severity: Critical
EPSS: 0.9998
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Concern