connectwise has 2 CVEs on record between 2019 and 2026. 1 was published in the last 90 days. The median CVSS is 9.9 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 100% vs 1% corpus
- Median CVSS
- 9.9
- Publish → KEV
- —(2)
- Last 90 days
- 1 prev 0
Worst active — by depth score
CVE-2017-18362Critical· 9.8ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database100CVE-2026-84869Critical· 9.9A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances80
connectwise vulnerabilities
CVEs affecting connectwise, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-84869Critical· 9.9CISA KEVPoCA condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVE-2017-18362Critical· 9.8CISA KEVPoCConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the …