Organizations using ConnectWise ScreenConnect should apply the latest patches provided by ConnectWise immediately. Federal civilian executive branch agencies are required to patch by September 30, 2026, per CISA's binding operational directive. Additionally, organizations should monitor for any signs of compromise, review remote access logs, and consider restricting network access to ScreenConnect instances until patching is complete.
Quick answers
What is CVE-2024-1709?
Organizations using ConnectWise ScreenConnect should apply the latest patches provided by ConnectWise immediately. Federal civilian executive branch agencies are required to patch by September 30, 2026, per CISA's binding operational directive. Additionally, organizations should monitor for any signs of compromise, review remote access logs, and consider restricting network access to ScreenConnect instances until patching is complete.
How severe is CVE-2024-1709?
critical
Is CVE-2024-1709 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2024-1709 be mitigated?
Organizations using ConnectWise ScreenConnect should apply the latest patches provided by ConnectWise immediately. Federal civilian executive branch agencies are required to patch by September 30, 2026, per CISA's binding operational directive. Additionally, organizations should monitor for any signs of compromise, review remote access logs, and consider restricting network access to ScreenConnect instances until patching is complete.
CVSS
—
Vendor
ConnectWise
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
ScreenConnect
Mitigation
Organizations using ConnectWise ScreenConnect should apply the latest patches provided by ConnectWise immediately. Federal civilian executive branch agencies are required to patch by September 30, 2026, per CISA's binding operational directive. Additionally, organizations should monitor for any signs of compromise, review remote access logs, and consider restricting network access to ScreenConnect instances until patching is complete.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-1709, a critical-severity vulnerability in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities (KEV) catalog following confirmed active exploitation. The flaw allows remote code execution, and CISA has issued a binding operational directive requiring federal civilian agencies to patch by September 30, 2026. Organizations using ScreenConnect are urged to apply the latest patches immediately.