Brand
ConnectWise: actively exploited vulnerabilities
4 vulnerabilities in ConnectWise products (ScreenConnect) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: September 11, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
2 vulnerabilities added in the last 12 months
-
4 exploited vulnerabilities in the catalog, in total
-
1 added in the last 30 days
By category
Add just one ConnectWise category to your radar, or open its page.
- Remote monitoring and management (RMM) 4 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- ScreenConnect4 vulnerabilities, Remote management (RMM)
Name used by CISA: ConnectWise. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this ConnectWise list.
- Rank 1
ConnectWise ScreenConnectCVE-2026-84869
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 9.9critical
Added Sep 11, 2026
- Rank 2
ConnectWise ScreenConnectCVE-2024-1708
ConnectWise ScreenConnect Path Traversal Vulnerability
RansomwareCVE from 2024, added in 2026
CVSS severity 8.4high
Added Apr 28, 2026
- Rank 3
ConnectWise ScreenConnectCVE-2024-1709
ConnectWise ScreenConnect Authentication Bypass Vulnerability
Ransomware
CVSS severity 10.0critical
Added Feb 22, 2024
- Rank 4
ConnectWise ScreenConnectCVE-2025-3935
ConnectWise ScreenConnect Improper Authentication Vulnerability
CVSS severity 7.2high
Added Jun 2, 2025
Follow and verify
Indicative classification, based on the vendor and product names given by CISA. How products are classified.