ConnectWise Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for ConnectWise products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
4
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
ConnectWise KEVs Added by Year
4 ConnectWise KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2024-1708
Improper limitation of a pathname to a restricted directory (“path traversal”) |
ScreenConnect | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-3935
ScreenConnect Exposure to ASP.NET ViewState Code Injection |
ScreenConnect | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2017-18362
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to... |
ManagedITSync integration for Kaseya VSA | Confirmed | In CISA | 24 May 2022 |
|
CVE-2024-1709
Authentication bypass using an alternate path or channel |
ScreenConnect | Confirmed | In CISA | 22 Feb 2024 |
Common Vulnerability Classes (CWE)
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-288 — Authentication Bypass Using an Alternate Path or Channel 1
- CWE-502 — Deserialization of Untrusted Data 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology