FAIL › dossier
ConnectWise
VENDOR· dossier confidence 20%
ConnectWise faces significant security risks due to repeated critical vulnerabilities in its ScreenConnect platform, including active exploitation of RCE and authentication bypass flaws.
PROFILE
CategoryManaged Service Provider (MSP) / IT InfrastructureWhat they doConnectWise provides IT management and remote access solutions, primarily through its ScreenConnect platform, serving Managed Service Providers and enterprises.
Websitehttps://www.connectwise.com ↗
SECURITY POSTURE
Demonstrates a pattern of critical remote code execution and authentication bypass vulnerabilities in ScreenConnect, with active exploitation in the wild despite patching.
Notable failures
- CVE-2024-1708 critical RCE enabling ransomware
- CVE-2024-1709 critical authentication bypass creating admin accounts
- CVE-2025-3935 high RCE actively exploited in the wild
Patterns: Repeated critical RCE vulnerabilities in ScreenConnect; Active exploitation of unpatched vulnerabilities in the wild
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-04-28 | CVE-2024-1708 | critical | ConnectWise ScreenConnect exploited via CVE-2024-1708 enables remote code execution and ransomware-linked attacks. |
| 2024-02-22 | CVE-2024-1709 | critical | An authentication bypass flaw in ConnectWise ScreenConnect lets attackers create admin accounts on affected devices. |
| 2025-06-02 | CVE-2025-3935 | high | ConnectWise ScreenConnect had remote code execution vulnerability actively exploited in the wild |
| 2019-02-05 | CVE-2017-18362 | critical | CVE-2017-18362: ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
ConnectWise's vulnerability in ManagedITSync integration allowed unauthenticated remote commands, leading to active ransomware exploitation in the wild by February 2019, causing severe fallout for the
ConnectWise's vulnerability in ManagedITSync integration allowed unauthenticated remote commands, leading to active ransomware exploitation in the wild by February 2019, causing severe fallout for the
"ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server."
DOSSIER SOURCES
- Audit page - ConnectWise · docs.connectwise.com
- What the ConnectWise 2025 MSP Threat Report Says About Managed Service ... · stats.conversationalgeek.com
- Remediate vulnerabilities for CVE-2025-5777 - docs.netscaler.com · docs.netscaler.com
Open questions: ConnectWise's remediation timeline for CVE-2025-3935 · Impact of CVE-2024-1708 on current customer base
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:46:22.576156+00:00