Skip to content
COOEY

FAIL › dossier

ConnectWise

VENDOR

· dossier confidence 20%

ConnectWise faces significant security risks due to repeated critical vulnerabilities in its ScreenConnect platform, including active exploitation of RCE and authentication bypass flaws.

PROFILE
CategoryManaged Service Provider (MSP) / IT InfrastructureWhat they doConnectWise provides IT management and remote access solutions, primarily through its ScreenConnect platform, serving Managed Service Providers and enterprises. Websitehttps://www.connectwise.com ↗
SECURITY POSTURE

Demonstrates a pattern of critical remote code execution and authentication bypass vulnerabilities in ScreenConnect, with active exploitation in the wild despite patching.

Notable failures
  • CVE-2024-1708 critical RCE enabling ransomware
  • CVE-2024-1709 critical authentication bypass creating admin accounts
  • CVE-2025-3935 high RCE actively exploited in the wild
Patterns: Repeated critical RCE vulnerabilities in ScreenConnect; Active exploitation of unpatched vulnerabilities in the wild
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2026-04-28 CVE-2024-1708 critical ConnectWise ScreenConnect exploited via CVE-2024-1708 enables remote code execution and ransomware-linked attacks.
2024-02-22 CVE-2024-1709 critical An authentication bypass flaw in ConnectWise ScreenConnect lets attackers create admin accounts on affected devices.
2025-06-02 CVE-2025-3935 high ConnectWise ScreenConnect had remote code execution vulnerability actively exploited in the wild
2019-02-05 CVE-2017-18362 critical CVE-2017-18362: ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
ConnectWise's vulnerability in ManagedITSync integration allowed unauthenticated remote commands, leading to active ransomware exploitation in the wild by February 2019, causing severe fallout for the
cooey ↗severe-fallout-0.80
ConnectWise's vulnerability in ManagedITSync integration allowed unauthenticated remote commands, leading to active ransomware exploitation in the wild by February 2019, causing severe fallout for the
"ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server."
Open questions: ConnectWise's remediation timeline for CVE-2025-3935 · Impact of CVE-2024-1708 on current customer base
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:46:22.576156+00:00