Daily Digest

Urgent Patch Alert: Critical ConnectWise ScreenConnect Flaw (CVSS 10.0) Under Active Exploitation

Urgent Patch Alert: Critical ConnectWise ScreenConnect Flaw (CVSS 10.0) Under Active Exploitation

February 10, 2026
1 article (1 new)
10 min read

Summary

This advisory covers a critical cybersecurity event on February 10, 2026, centered on the active exploitation of two severe vulnerabilities in ConnectWise ScreenConnect. A CVSS 10.0 authentication bypass flaw (CVE-2026-1014) and a high-severity path traversal vulnerability (CVE-2026-1219) are being chained by attackers to achieve remote code execution on unpatched on-premise servers. CISA has added the critical flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate action. Organizations using ScreenConnect versions 23.9.7 and older are urged to upgrade to version 23.9.8 or later immediately or take servers offline to prevent compromise.

Filter by Category

📢 Share This Publication

Help others stay informed about cybersecurity threats