Skip to content
English

Products › IT administration and security

IT administration and security

Remote monitoring and management (RMM)

Remote support and remote management tools for workstations, much favored by attackers.

For example: ScreenConnect, SimpleHelp, Kaseya VSA, BeyondTrust.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • BeyondTrust 3 vulnerabilities · 1 in the last 12 months
  • ConnectWise 4 vulnerabilities · 2 in the last 12 months
  • Kaseya 3 vulnerabilities
  • N-able 5 vulnerabilities · 3 in the last 12 months
  • SimpleHelp 4 vulnerabilities · 3 in the last 12 months
  • TeamViewer 1 vulnerability

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1ConnectWise ScreenConnect

    CVE-2026-84869

    Recently addedHunt for compromise (CISA)

    ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 11, 2026
    CISA deadline
    3 days
    CVSS severity
    9.9 (critical)
  2. Rank 2N-able N-central

    CVE-2026-86218

    Recently addedHunt for compromise (CISA)

    N-able N-central Static Code Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 8, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3SimpleHelp

    CVE-2026-48558

    SimpleHelp Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 29, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  4. Rank 4SimpleHelp

    CVE-2024-57726

    RansomwareCVE from 2024, added in 2026

    SimpleHelp Missing Authorization Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 24, 2026
    CISA deadline
    14 days
    CVSS severity
    9.9 (critical)
  5. Rank 5BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)

    CVE-2026-1731

    Ransomware

    BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 13, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  6. Rank 6ConnectWise ScreenConnect

    CVE-2024-1708

    RansomwareCVE from 2024, added in 2026

    ConnectWise ScreenConnect Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 28, 2026
    CISA deadline
    14 days
    CVSS severity
    8.4 (high)
  7. Rank 7N-able N-central

    CVE-2026-18577

    Hunt for compromise (CISA)

    N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 3, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  8. Rank 8N-able N-central

    CVE-2026-18556

    Hunt for compromise (CISA)

    N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 4, 2026
    CISA deadline
    3 days
    CVSS severity
    7.4 (high)
  9. Rank 9SimpleHelp

    CVE-2024-57728

    RansomwareCVE from 2024, added in 2026

    SimpleHelp Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 24, 2026
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  10. Rank 10ConnectWise ScreenConnect

    CVE-2024-1709

    Ransomware

    ConnectWise ScreenConnect Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 22, 2024
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
Show 9 more vulnerabilities
  1. Rank 11BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)

    CVE-2024-12356

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 19, 2024
    CISA deadline
    8 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Kaseya VSA

    CVE-2018-20753

    RansomwareCVE from 2018, added in 2022

    Kaseya VSA Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Kaseya VSA

    CVE-2021-30116

    Ransomware

    Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  4. Rank 14N-able N-central

    CVE-2025-8876

    N-able N-Central Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2025
    CISA deadline
    7 days
    CVSS severity
    8.8 (high)
  5. Rank 15N-able N-central

    CVE-2025-8875

    N-able N-Central Insecure Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2025
    CISA deadline
    7 days
    CVSS severity
    7.8 (high)
  6. Rank 16SimpleHelp

    CVE-2024-57727

    Ransomware

    SimpleHelp Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  7. Rank 17ConnectWise ScreenConnect

    CVE-2025-3935

    ConnectWise ScreenConnect Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  8. Rank 18BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)

    CVE-2024-12686

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  9. Rank 19TeamViewer Desktop

    CVE-2019-18988

    CVE from 2019, added in 2021

    TeamViewer Desktop Bypass Remote Login Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.0 (high)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Kaseya VSA

    CVE-2017-18362

    RansomwareEnd of lifeCVE from 2017, added in 2022

    Kaseya VSA SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.