Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

ConnectWise LLC

First CVE: Jul 31, 2017Active for: 9 yearsTotal CVEs: 37
70.1
VTI Score
TOP TARGET

ConnectWise LLC develops remote-access, automation, and professional-services management platforms widely deployed across managed-service providers and IT operations environments, creating a concentrated but high-value attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have both an elevated tendency to be cataloged as known-exploited by CISA and a strong pattern of acquiring public exploit tooling, reflecting the appeal of these products as pivot points and operational targets. The exposure recurs across Automate, Control, ScreenConnect, and the professional-services automation suite through weakness classes including SQL injection, cleartext credential transmission, unsigned code download, and cross-site scripting—input-handling and trust-boundary flaws endemic to web-based remote-management software. Defenders should treat ConnectWise advisories as urgent, inventory all internet-facing instances, and prioritize patching these products alongside critical network infrastructure; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
More Total CVEs than 98% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
10.8%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by ConnectWise LLC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2017
8 years ago
Most Recent CVE
May 21, 2026
64 days ago

Self-Reporting Analysis

Of all the CVEs published by ConnectWise LLC as a CNA, 84.6% affect products that ConnectWise LLC develops as a vendor.

84.6%
15.4%
Self-reported: 11 (84.6%)
Third-party: 2 (15.4%)

Of all the CVEs published that affect products developed by ConnectWise LLC, 29.7% are self-published by ConnectWise LLC as a CNA.

29.7%
70.3%
Self-published: 11 (29.7%)
Other CNAs: 26 (70.3%)

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-1709CRITICAL
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to
Feb 21, 202410.099YESYES
CVE-2024-1708HIGH
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confide
Feb 21, 20248.497YESYES
CVE-2017-18362CRITICAL
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In Febr
Feb 5, 20199.897YESYES
CVE-2025-3935HIGH
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with
Apr 25, 20257.263YESNO
CVE-2026-9089HIGH
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate
May 21, 20268.839NONO
CVE-2019-16516MEDIUM
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to
Jan 23, 20205.337NOYES
CVE-2025-14265CRITICAL
In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or a
Dec 11, 20259.132NONO
CVE-2020-15027CRITICAL
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7
Jul 16, 20209.830NONO
CVE-2025-11492HIGH
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position
Oct 16, 20257.529NONO
CVE-2023-25718CRITICAL
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signa
Feb 13, 20239.828NONO
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
41%
41%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (5.4%)
Network32 (86.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (8.1%)
Attack Complexity
Low31 (83.8%)
High6 (16.2%)
Unknown0 (0.0%)
User Interaction
None26 (70.3%)
Unknown0 (0.0%)
Required11 (29.7%)
Privileges Required
Low7 (18.9%)
High6 (16.2%)
None24 (64.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
4 CVEs
10.8% of CVEs· 100th percentile
Metasploit
2 CVEs
5.4% of CVEs· 98th percentile
Nuclei
2 CVEs
5.4% of CVEs· 96th percentile
ExploitDB
1 CVE
2.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by ConnectWise LLC.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by ConnectWise LLC — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For ConnectWise LLC's Products

View all 4 CNAs →

Top CWEs