This advisory covers a critical cybersecurity event on February 10, 2026, centered on the active exploitation of two severe vulnerabilities in ConnectWise ScreenConnect. A CVSS 10.0 authentication bypass flaw (CVE-2026-1014) and a high-severity path traversal vulnerability (CVE-2026-1219) are being chained by attackers to achieve remote code execution on unpatched on-premise servers. CISA has added the critical flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate action. Organizations using ScreenConnect versions 23.9.7 and older are urged to upgrade to version 23.9.8 or later immediately or take servers offline to prevent compromise.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.