ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker
the ability to execute remote code or directly impact confidential data or critical systems.
Details
CVSS Score
8.4
EPSS Score
ⓘ
87.62%
99.7th percentile
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Confidence
100%
Published
Feb 21, 2024
Last Modified
Aug 4, 2026
CISA KEV
Date Added
Apr 28, 2026
Patch Due
May 12, 2026
Used in ransomware campaigns
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.