Where
-Infinity
0

ConnectWise ScreenConnectIn ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionali…

Risk 36
Severity
4.7
First published (updated )

ConnectWise ConnectWise Automate AgentThe ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during…

Risk 56
Severity
8.8
EPSS
0.31%
First published (updated )

ConnectWise Connectwise AutomateUnencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center

Risk 35
Severity
7.1
EPSS
0.01%
First published (updated )

First UniFi With a 10.0 CVE, Now ScreenConnect 9.0 CVE

First published (updated )
Social
reddit

BleepingComputerConnectWise patches new flaw allowing ScreenConnect hijacking

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ConnectWise ScreenConnectScreenConnect Instance Level Cryptographic Material Exposure

Risk 58
Severity
9
EPSS
0.03%
First published (updated )

ConnectWise ConnectWise PSASession Cookies Missing HttpOnly Attribute

Risk 27
Severity
6.5
EPSS
0.05%
First published (updated )

ConnectWise PSAStored XSS in Time Entry Audit Trail

Risk 45
Severity
8.7
EPSS
0.03%
First published (updated )

ScreenConnect Certificate Signing ExtensionCertificate Signing Extension Returns Encrypted Values

Risk 27
Severity
5.3
First published (updated )

ScreenConnect ScreenConnectImproper server-side validation in ScreenConnect extension framework

Risk 72
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerConnectWise fixes Automate bug allowing AiTM update attacks

First published (updated )

ConnectWise AutomateSelf-Update Verification Mechanism Process in ConnectWise Automate

Risk 82
Severity
8.8
First published (updated )

ConnectWise Automate AgentHTTP Configuration and Encryption in Transit

Risk 85
Severity
9.6
First published (updated )

ConnectWise PSAExposure of password hashes via API responses in ConnectWise PSA

Risk 27
Severity
6.5
EPSS
0.04%
First published (updated )

BleepingComputerHackers turn ScreenConnect into malware using Authenticode stuffing

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerConnectWise rotating code signing certificates over security concerns

First published (updated )

The RegisterConnectWise customers get mysterious warning about 'sophisticated' nation-state hack

First published (updated )

BleepingComputerConnectWise breached in cyberattack linked to nation-state hackers

First published (updated )

ConnectWise Password Encryption UtilityHardcoded Key Revealed in ConnectWise Password Encryption Utility

Risk 24
Severity
6
EPSS
0.01%
First published (updated )

ConnectWise ScreenConnectConnectWise ScreenConnect Improper Authentication Vulnerability

Risk 71
Severity
8.1
EPSS
0.26%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

The RegisterMedusa ransomware infects 300+, uses 'triple extortion'

First published (updated )

Dark ReadingHow Public & Private Sectors Can Better Align Cyber Defense

First published (updated )

The RegisterRussia's Sandworm caught snarfing credentials, data from American and Brit orgs

First published (updated )

Dark ReadingMicrosoft: Russia's Sandworm APT Exploits Edge Bugs Globally

First published (updated )

The RegisterChinese snoops exploit F5, ConnectWise bugs to sell access

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

The RegisterUS to probe Change Healthcare's data protection standards as lawsuits mount

First published (updated )

BleepingComputerMagnet Goblin hackers use 1-day flaws to drop custom Linux malware

First published (updated )

BleepingComputerScreenConnect flaws exploited to drop new ToddleShark malware

First published (updated )

BleepingComputerBlack Basta, Bl00dy ransomware gangs join ScreenConnect attacks

First published (updated )

ConnectWise ScreenConnectConnectWise ScreenConnect Authentication Bypass Vulnerability

Risk 100
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203