
CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-1709, a critical-severity vulnerability in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities (KEV) catalog following confirmed active exploitation. The flaw allows remote code execution, and CISA has issued a binding operational directive requiring federal civilian agencies to patch by September 30, 2026. Organizations using ScreenConnect are urged to apply the latest patches immediately.



_Ivelin_Radkov_Alamy.png?width=720&quality=80&disable=upscale)