ConnectWise ScreenConnect Authentication Bypass Under Active Exploitation Grants Full Remote Control of Managed Endpoints (CVE-2026-77924)
Scope: ConnectWise ScreenConnect (All Versions Prior to Latest Patched Release)
Severity: Red
A critical authentication bypass vulnerability in ConnectWise ScreenConnect, a widely deployed remote monitoring and management tool used by IT teams and managed service providers across Uganda, is under active exploitation and was added to CISA's Known Exploited Vulnerabilities catalog with a federal deadline of September 14, 2026. Unauthenticated attackers who exploit CVE-2026-77924 gain complete remote control over every endpoint managed through the compromised ScreenConnect instance, enabling silent credential theft, ransomware deployment, persistent backdoor installation, and lateral movement across every client environment connected to the platform. Organizations must update ScreenConnect to the latest patched version immediately, restrict access to the ScreenConnect management interface to trusted IP addresses only, audit connected endpoints for signs of unauthorized remote sessions, and treat any instance that was internet-exposed before patching as potentially compromised.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.