Skip to main content

Vendor archive

connectwise CVEs

Beta · best-effort

37 CVEs tagged to vendor connectwise8 Critical, 15 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2026-9089

Published May 21, 2026

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6066

Published Apr 20, 2026

ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communica…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0696

Published Jan 16, 2026

In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0695

Published Jan 16, 2026

In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under spe…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-14823

Published Dec 18, 2025

In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticate…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14265

Published Dec 11, 2025

In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11493

Published Oct 16, 2025

The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk whe…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-11492

Published Oct 16, 2025

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network positio…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-4876

Published May 19, 2025

ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedd…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3935

Published Apr 25, 2025

ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, wit…

CVSS 8.1 · High
evidence mentions
4
Buzz score
49.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-1709

Published Feb 21, 2024

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access t…

CVSS 10.0 · Critical
evidence mentions
32
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-1708

Published Feb 21, 2024

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confid…

CVSS 8.4 · High
evidence mentions
22
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2023-25719

Published Feb 13, 2023

ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiseControl.Client.exe h parameter. This…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25718

Published Feb 13, 2023

In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the sign…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23130

Published Feb 1, 2023

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23128

Published Feb 1, 2023

Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23127

Published Feb 1, 2023

In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is that, by design, this is contr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23126

Published Feb 1, 2023

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36781

Published Sep 28, 2022

ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32582

Published Jun 17, 2021

An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15838

Published Oct 9, 2020

The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2