ScreenConnect
ConnectWise- Product type
- Other
- Catalog vulnerabilities
- 11
Severity across 9 analyzed records
Verify to analyze this security profile
en
Severity across 9 analyzed records
Verify to analyze this security profile
As of 09/20/2026, within CyStack's analyzed data, ScreenConnect has 1 security vulnerability published in the last 90 days. Of these, 1 is rated High or Critical. Notably, 1 of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of ScreenConnect and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-84869ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions | Exploitation statusKEV | FixYes | Published09/08/2026 | SeverityCritical |
CVE-2026-11596 | Exploitation statusNot known exploited | FixYes | Published06/10/2026 | SeverityMedium |
CVE-2026-3564ScreenConnect Instance Level Cryptographic Material Exposure | Exploitation statusNot known exploited | FixYes | Published03/17/2026 | SeverityCritical |
CVE-2025-14823Certificate Signing Extension Returns Encrypted Values | Exploitation statusNot known exploited | FixNot confirmed | Published12/18/2025 | SeverityMedium |
CVE-2025-14265Improper server-side validation in ScreenConnect extension framework | Exploitation statusNot known exploited | FixYes | Published12/11/2025 | SeverityCritical |
CVE-2025-3935ScreenConnect Exposure to ASP.NET ViewState Code Injection | Exploitation statusKEV | FixYes | Published04/25/2025 | SeverityHigh |
CVE-2024-1709Authentication bypass using an alternate path or channel | Exploitation statusKEV | FixYes | Published02/21/2024 | SeverityCritical |
CVE-2024-1708Improper limitation of a pathname to a restricted directory (“path traversal”) | Exploitation statusKEV | FixYes | Published02/21/2024 | SeverityHigh |
CVE-2023-47256 | Exploitation statusNot known exploited | FixNot confirmed | Published02/01/2024 | SeverityMedium |
CVE-2023-47257 | Exploitation statusNot known exploited | FixNot confirmed | Published02/01/2024 | SeverityHigh |
CVE-2022-36781ConnectWise - ScreenConnect Session Code Bypass | Exploitation statusNot confirmed | FixYes | Published09/28/2022 | SeverityMedium |