ConnectWise security briefs
3 published alerts for ConnectWise products and services.
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-84869). ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. CISA remediation due date: 2026-09-14. If you need help checking exposure, call (864) 335-9223.
ConnectWise ScreenConnect Path Traversal Vulnerability
ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1708). ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. CISA remediation due date: 2026-05-12. If you need help checking exposure, call (864) 335-9223.
ConnectWise ScreenConnect Authentication Bypass Vulnerability
ConnectWise ScreenConnect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1709). ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices. CISA remediation due date: 2024-02-29. If you need help checking exposure, call (864) 335-9223.