Vendor

ConnectWise

As of , 4 ConnectWise vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2024-1708.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2024-1708Path TraversalConnectWise ScreenConnectPatch nowRansomware use, listed within a year; Metasploit module0.95
2CVE-2026-84869Improper Privilege Management and Missing AuthorizationConnectWise ScreenConnectPatch nowForensic triage required by CISA0.01
3CVE-2024-1709Authentication BypassConnectWise ScreenConnectPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
4CVE-2025-3935Improper AuthenticationConnectWise ScreenConnectPatch soon0.04

Added each year

0.511.522024: 1120242025: 1120252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20241
20251
20262

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-84869 ConnectWise ScreenConnectEdited: description.
  2. CVE-2024-1708 ConnectWise ScreenConnectRansomware use: Unknown to Known.

Every change we recorded