ConnectWise LLC develops remote-access, automation, and professional-services management platforms widely deployed across managed-service providers and IT operations environments, creating a concentrated but high-value attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have both an elevated tendency to be cataloged as known-exploited by CISA and a strong pattern of acquiring public exploit tooling, reflecting the appeal of these products as pivot points and operational targets. The exposure recurs across Automate, Control, ScreenConnect, and the professional-services automation suite through weakness classes including SQL injection, cleartext credential transmission, unsigned code download, and cross-site scripting—input-handling and trust-boundary flaws endemic to web-based remote-management software. Defenders should treat ConnectWise advisories as urgent, inventory all internet-facing instances, and prioritize patching these products alongside critical network infrastructure; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by ConnectWise LLC over time
Of all the CVEs published by ConnectWise LLC as a CNA, 84.6% affect products that ConnectWise LLC develops as a vendor.
Of all the CVEs published that affect products developed by ConnectWise LLC, 29.7% are self-published by ConnectWise LLC as a CNA.
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1709CRITICAL ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel
vulnerability, which may allow an attacker direct access to | Feb 21, 2024 | 10.0 | 99 | YES | YES |
CVE-2024-1708HIGH ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker
the ability to execute remote code or directly impact confide | Feb 21, 2024 | 8.4 | 97 | YES | YES |
CVE-2017-18362CRITICAL ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In Febr | Feb 5, 2019 | 9.8 | 97 | YES | YES |
CVE-2025-3935HIGH ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with | Apr 25, 2025 | 7.2 | 63 | YES | NO |
CVE-2026-9089HIGH The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate | May 21, 2026 | 8.8 | 39 | NO | NO |
CVE-2019-16516MEDIUM An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to | Jan 23, 2020 | 5.3 | 37 | NO | YES |
CVE-2025-14265CRITICAL In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or a | Dec 11, 2025 | 9.1 | 32 | NO | NO |
CVE-2020-15027CRITICAL ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 | Jul 16, 2020 | 9.8 | 30 | NO | NO |
CVE-2025-11492HIGH In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position | Oct 16, 2025 | 7.5 | 29 | NO | NO |
CVE-2023-25718CRITICAL In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signa | Feb 13, 2023 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by ConnectWise LLC.
Media articles that mention a CVE ID that affects a product developed by ConnectWise LLC — matched by CVE ID, not by vendor name.