Connectwise
Connectwise Screenconnect: vulnerabilidades y CVE
Connectwise Screenconnect tiene 11 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 4 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses5
Críticas4
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84869 | Crítica (9.9) | 0.92% | ⚠ Explotación activa | 8 sept 2026 | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not… |
| CVE-2024-1708 | Alta (8.4) | 95% | ⚠ Explotación activa | 21 feb 2024 | ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems. |
| CVE-2025-3935 | Alta (7.2) | 3.5% | ⚠ Explotación activa | 25 abr 2025 | ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by… |
| CVE-2024-1709 | Crítica (10) | 100% | ⚠ Explotación activa | 21 feb 2024 | ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84869 | Crítica (9.9) | 0.92% | ⚠ Explotación activa | 8 sept 2026 | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not… |
| CVE-2026-11596 | Media (4.7) | 0.24% | — | 10 jun 2026 | In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration… |
| CVE-2026-3564 | Crítica (9) | 0.28% | — | 17 mar 2026 | A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain… |
| CVE-2025-14823 | Media (5.3) | 0.15% | — | 18 dic 2025 | In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint… |
| CVE-2025-14265 | Crítica (9.1) | 0.37% | — | 11 dic 2025 | In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or… |
| CVE-2025-3935 | Alta (7.2) | 3.5% | ⚠ Explotación activa | 25 abr 2025 | ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by… |
| CVE-2024-1709 | Crítica (10) | 100% | ⚠ Explotación activa | 21 feb 2024 | ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical… |
| CVE-2024-1708 | Alta (8.4) | 95% | ⚠ Explotación activa | 21 feb 2024 | ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems. |
| CVE-2023-47257 | Alta (8.1) | 1.0% | — | 1 feb 2024 | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. |
| CVE-2023-47256 | Media (5.5) | 0.45% | — | 1 feb 2024 | ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings |
| CVE-2022-36781 | Media (5.3) | 0.62% | — | 28 sept 2022 | ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.