CVE-2024-1709: ConnectWise ScreenConnect Authentication Bypass Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.
CSIRTS triage
- What
- An authentication bypass vulnerability allows attackers to create a new administrator-level account on affected devices.
- Who is affected
- Users of ConnectWise ScreenConnect are affected.
- Urgency
- Remediation is urgent as the vulnerability has been exploited in the wild.
- Action
- Apply the necessary patches or updates to ScreenConnect.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ScreenConnect
Get an email when a new ScreenConnect advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-1709
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2024-1709Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2024-1709 | coverage & exploitation status | NVD · CVE.org |
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability2026-09-11
- criticalCVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability2026-09-11
- criticalCVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability2026-09-11
- criticalCVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerabilit…2026-09-11
- criticalCVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability2026-09-10