CVE-2025-14265Critical· 9.1▾ MidnightIn versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.
screenconnect < 25.8.0.9438Upgrade past the affected range:
screenconnect 25.8.0.9438Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84869Critical· 9.9A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances
CVE-2017-18362Critical· 9.8ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database
CVE-2025-66332Low· 3.3Denial of service (DoS) vulnerability in the office service
CVE-2025-66333Low· 3.3Denial of service (DoS) vulnerability in the office service
CVE-2025-66334Low· 3.3Denial of service (DoS) vulnerability in the office service
CVE-2025-66331Low· 3.3Denial of service (DoS) vulnerability in the office service