ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker
the ability to execute remote code or directly impact confidential data or critical systems.
Is CVE-2024-1708 exploited?
Listed in the CISA KEV catalog on 2026-04-28.
Federal remediation due 2026-05-12.
Past that date by 95 days.
EPSS puts exploitation in the next 30 days at 88%.
Public exploit code: packaged in a public tool.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2024-1708
PlainSec has not published a story about this CVE.