Products › IT administration and security
IT administration and security
Remote monitoring and management (RMM)
Remote support and remote management tools for workstations, much favored by attackers.
For example: ScreenConnect, SimpleHelp, Kaseya VSA, BeyondTrust.
-
9 vulnerabilities added in the last 12 months
-
20 exploited vulnerabilities in the catalog, in total
-
2 added in the last 30 days
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- BeyondTrust 3 vulnerabilities · 1 in the last 12 months
- ConnectWise 4 vulnerabilities · 2 in the last 12 months
- Kaseya 3 vulnerabilities
- N-able 5 vulnerabilities · 3 in the last 12 months
- SimpleHelp 4 vulnerabilities · 3 in the last 12 months
- TeamViewer 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Monitoring, ITSM and asset management 78 vulnerabilities
- Firewalls, VPNs and remote access 111 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
- Rank 1
ConnectWise ScreenConnectCVE-2026-84869
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 9.9critical
Added Sep 11, 2026
- Rank 2
N-able N-centralCVE-2026-86218
N-able N-central Static Code Injection Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 9.8critical
Added Sep 8, 2026
- Rank 3
SimpleHelpCVE-2026-48558
SimpleHelp Authentication Bypass Vulnerability
CVSS severity 10.0critical
Added Jun 29, 2026
- Rank 4
SimpleHelpCVE-2024-57726
SimpleHelp Missing Authorization Vulnerability
RansomwareCVE from 2024, added in 2026
CVSS severity 9.9critical
Added Apr 24, 2026
- Rank 5
BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)CVE-2026-1731
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Feb 13, 2026
- Rank 6
ConnectWise ScreenConnectCVE-2024-1708
ConnectWise ScreenConnect Path Traversal Vulnerability
RansomwareCVE from 2024, added in 2026
CVSS severity 8.4high
Added Apr 28, 2026
- Rank 7
N-able N-centralCVE-2026-18577
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Hunt for compromise (CISA)
CVSS severity 8.1high
Added Aug 3, 2026
- Rank 8
N-able N-centralCVE-2026-18556
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Hunt for compromise (CISA)
CVSS severity 7.4high
Added Aug 4, 2026
- Rank 9
SimpleHelpCVE-2024-57728
SimpleHelp Path Traversal Vulnerability
RansomwareCVE from 2024, added in 2026
CVSS severity 7.2high
Added Apr 24, 2026
- Rank 10
ConnectWise ScreenConnectCVE-2024-1709
ConnectWise ScreenConnect Authentication Bypass Vulnerability
Ransomware
CVSS severity 10.0critical
Added Feb 22, 2024
Show 9 more vulnerabilities
- Rank 11
BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)CVE-2024-12356
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
CVSS severity 9.8critical
Added Dec 19, 2024
- Rank 12
Kaseya VSACVE-2018-20753
Kaseya VSA Remote Code Execution Vulnerability
RansomwareCVE from 2018, added in 2022
CVSS severity 9.8critical
Added Apr 13, 2022
- Rank 13
Kaseya VSACVE-2021-30116
Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 14
N-able N-centralCVE-2025-8876
N-able N-Central Command Injection Vulnerability
CVSS severity 8.8high
Added Aug 13, 2025
- Rank 15
N-able N-centralCVE-2025-8875
N-able N-Central Insecure Deserialization Vulnerability
CVSS severity 7.8high
Added Aug 13, 2025
- Rank 16
SimpleHelpCVE-2024-57727
SimpleHelp Path Traversal Vulnerability
Ransomware
CVSS severity 7.5high
Added Feb 13, 2025
- Rank 17
ConnectWise ScreenConnectCVE-2025-3935
ConnectWise ScreenConnect Improper Authentication Vulnerability
CVSS severity 7.2high
Added Jun 2, 2025
- Rank 18
BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)CVE-2024-12686
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability
CVSS severity 7.2high
Added Jan 13, 2025
- Rank 19
TeamViewer DesktopCVE-2019-18988
TeamViewer Desktop Bypass Remote Login Vulnerability
CVE from 2019, added in 2021
CVSS severity 7.0high
Added Nov 3, 2021
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
Kaseya VSACVE-2017-18362
Kaseya VSA SQL Injection Vulnerability
RansomwareEnd of lifeCVE from 2017, added in 2022
CVSS severity 9.8critical
Added May 24, 2022
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.