FAIL › dossier
ScreenConnect
PRODUCT· dossier confidence 20%
ConnectWise's ScreenConnect platform has a history of critical security vulnerabilities, including remote code execution and authentication bypass flaws, which have been actively exploited. This poses a significant risk to organizations utilizing the software and necessitates immediate security improvements.
PROFILE
Categoryremote access softwareWhat they doScreenConnect is a remote access and support software solution used for providing technical support and remote system management. It enables users to remotely access and control devices.
Websitehttps://screenconnect.com/ ↗
SECURITY POSTURE
ScreenConnect demonstrates a pattern of critical remote code execution and authentication bypass vulnerabilities, with active exploitation in the wild. This indicates a significant risk profile requiring immediate attention and remediation.
Notable failures
- CVE-2024-1708 (critical RCE)
- CVE-2024-1709 (critical authentication bypass)
- CVE-2025-3935 (high RCE)
Patterns: repeated critical remote code execution vulnerabilities; authentication bypass flaws; active exploitation in the wild
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-04-28 | CVE-2024-1708 | critical | ConnectWise ScreenConnect exploited via CVE-2024-1708 enables remote code execution and ransomware-linked attacks. |
| 2024-02-22 | CVE-2024-1709 | critical | An authentication bypass flaw in ConnectWise ScreenConnect lets attackers create admin accounts on affected devices. |
| 2025-06-02 | CVE-2025-3935 | high | ConnectWise ScreenConnect had remote code execution vulnerability actively exploited in the wild |
DOSSIER SOURCES
- VirusTotal - URL · www.virustotal.com
- Fitch Affirms ConnectWise's IDR at 'B+'; Outlook Stable · www.fitchratings.com
- Companies using ScreenConnect (active customer list) · bloomberry.com
Open questions: What is the current ownership structure of ConnectWise? · What is the size of ScreenConnect's development and security teams?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-04 04:06:57.251555+00:00