LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 28, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 12, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-1708 to its Known Exploited Vulnerabilities catalog on Apr 28, 2026, with a federal patch deadline of May 12, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

ConnectWise ScreenConnect contains a path traversal vulnerability. An attacker who can reach the affected system may be able to execute remote code or directly affect confidential data and critical systems. The vulnerability is known to have been used in ransomware attacks.

How it works

The weakness is classified as CWE-22, improper limitation of a pathname to a restricted directory. In this class of flaw an attacker supplies crafted input that causes the application to access or write files outside the intended directory. For a remote-access product such as ScreenConnect the result can be arbitrary file operations that lead to code execution or data exposure. Exact attack mechanics and prerequisites must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

How to remediate

Apply the vendor-supplied update or mitigation instructions as the primary action. For path-traversal weaknesses in remote-access software, additional hardening steps include restricting which directories the application can read or write and enforcing least-privilege service accounts. Follow any applicable CISA BOD 22-01 guidance for cloud services that host the product.

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to data breaches and ransomware deployment. Organizations can run a free exposure scan of their email domains against known breach data to determine whether credentials or other information have already appeared in public data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedConnectWise · ScreenConnect
WeaknessCWE-22
Added to CISA KEVApr 28, 2026
Federal patch deadlineMay 12, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities