VendorsConnectWisescreenconnectany version
Vulnerabilities

ConnectWise ScreenConnect any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-1709
Authentication bypass using an alternate path or channel
Published 2024-02-21 · Analyzed
10.0KEVEPSS 1.000
CVE-2026-84869
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
Published 2026-09-08 · Analyzed
9.9KEVEPSS 0.007
CVE-2025-14265
Improper server-side validation in ScreenConnect extension framework
Published 2025-12-11 · Analyzed
9.1EPSS 0.004
CVE-2024-1708
Improper limitation of a pathname to a restricted directory (“path traversal”)
Published 2024-02-21 · Analyzed
8.4KEVEPSS 0.955
CVE-2025-3935
ScreenConnect Exposure to ASP.NET ViewState Code Injection
Published 2025-04-25 · Analyzed
8.1KEVEPSS 0.035
CVE-2023-47257
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
Published 2024-02-01 · Modified
8.1EPSS 0.010
CVE-2023-47256
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
Published 2024-02-01 · Modified
5.5EPSS 0.004
CVE-2022-36781
ConnectWise - ScreenConnect Session Code Bypass
Published 2022-09-28 · Modified
5.3EPSS 0.005
CVE-2025-14823
Certificate Signing Extension Returns Encrypted Values
Published 2025-12-18 · Analyzed
5.3EPSS 0.002
CVE-2026-11596
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.
Published 2026-06-10 · Analyzed
4.7EPSS 0.002