ConnectWise LLC

First CVE: Apr 25, 2025Active for: 1 year
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
6.5
Avg CVEs / Year
More Avg CVEs / Year than 40% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked CNAs
7.7%
In CISA KEV
Higher KEV Rate than 97% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by ConnectWise LLC as a CNA, 84.6% affect products that ConnectWise LLC develops as a vendor.

84.6%
15.4%
Self-reported: 11Third-party: 2

Of all the CVEs published that affect products developed by ConnectWise LLC, 29.7% are self-published by ConnectWise LLC as a CNA.

29.7%
70.3%
Self-published: 11Published by other CNAs: 26

Trends Over Time

The number and severity of CVEs published by ConnectWise LLC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2025
14 months ago
Most Recent CVE
Jun 10, 2026
44 days ago

Top CVEs

All CVEs published by ConnectWise LLC as a CNA, regardless of affected vendor or product.

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with
Apr 25, 20257.263YESNO
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate
May 21, 20268.839NONO
A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, inclu
Mar 17, 20269.038NONO
In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or a
Dec 11, 20259.132NONO
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position
Oct 16, 20257.529NONO
The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk wher
Oct 16, 20257.527NONO
In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to s
Jan 16, 20266.526NONO
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communicat
Apr 20, 20267.124NONO
In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under spec
Jan 16, 20265.424NONO
In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sensitive user information. Specific API requests were found to
Jul 9, 20256.523NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA13 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (7.7%)
Network9 (69.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (23.1%)
Attack Complexity
Low10 (76.9%)
High3 (23.1%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low3 (23.1%)
High4 (30.8%)
None6 (46.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (13 CVEs).

CISA KEV
1 CVE
7.7% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by ConnectWise LLC as a CNA.

Media Mentions

Media articles that mention a CVE ID published by ConnectWise LLC as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs