Connectwise
Connectwise Screenconnect: vulnerabilities and CVEs
Connectwise Screenconnect has 11 published vulnerabilities, 5 of them in the last 12 months. 4 are rated critical and 4 are listed by CISA as actively exploited.
CVEs11
Last 12 months5
Critical4
Actively exploited4
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84869 | Critical (9.9) | 0.92% | ⚠ Active exploitation | Sep 8, 2026 | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not… |
| CVE-2024-1708 | High (8.4) | 95% | ⚠ Active exploitation | Feb 21, 2024 | ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems. |
| CVE-2025-3935 | High (7.2) | 3.5% | ⚠ Active exploitation | Apr 25, 2025 | ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by… |
| CVE-2024-1709 | Critical (10) | 100% | ⚠ Active exploitation | Feb 21, 2024 | ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84869 | Critical (9.9) | 0.92% | ⚠ Active exploitation | Sep 8, 2026 | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not… |
| CVE-2026-11596 | Medium (4.7) | 0.24% | — | Jun 10, 2026 | In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration… |
| CVE-2026-3564 | Critical (9) | 0.28% | — | Mar 17, 2026 | A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain… |
| CVE-2025-14823 | Medium (5.3) | 0.15% | — | Dec 18, 2025 | In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint… |
| CVE-2025-14265 | Critical (9.1) | 0.37% | — | Dec 11, 2025 | In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or… |
| CVE-2025-3935 | High (7.2) | 3.5% | ⚠ Active exploitation | Apr 25, 2025 | ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by… |
| CVE-2024-1709 | Critical (10) | 100% | ⚠ Active exploitation | Feb 21, 2024 | ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical… |
| CVE-2024-1708 | High (8.4) | 95% | ⚠ Active exploitation | Feb 21, 2024 | ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems. |
| CVE-2023-47257 | High (8.1) | 1.0% | — | Feb 1, 2024 | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. |
| CVE-2023-47256 | Medium (5.5) | 0.45% | — | Feb 1, 2024 | ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings |
| CVE-2022-36781 | Medium (5.3) | 0.62% | — | Sep 28, 2022 | ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.