🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

ConnectWise ScreenConnect Path Traversal RCE (CVE-2024-1708) | MSSP Advisory

Critical🔴 KEV ALERT
DateMay 3, 2026
CVECVE-2024-1708
CVSS Score8.4
AffectedScreenConnect
📋Executive Summary
ConnectWise ScreenConnect contains a critical path traversal vulnerability tracked as CVE-2024-1708 that allows remote code execution and direct access to confidential data. The vulnerability affects the remote access platform that many MSSPs use to manage client endpoints. Attackers can exploit this flaw to execute arbitrary code on systems running vulnerable ScreenConnect instances.
⚠️Why It Matters for MSSPs
Your ScreenConnect installation becomes a direct entry point into your entire client portfolio if compromised. Every client you manage through ScreenConnect sits behind this vulnerability, meaning one exploit gives attackers access to dozens of networks simultaneously. Your clients expect you to know when your remote access tools are compromised and act immediately.
Recommended Action
Update ScreenConnect to version 23.9.8 or later within 24 hours and verify the patch deployment across all instances you operate.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.