ConnectWise
ScreenConnect
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-84869 | 8 Sep 2026 | ScreenConnect: All versions prior to 26.6.5 | Cloud: Updated to the latest release. We recommend that; partners reinstall their host clients https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_client/Reinstall_the_host_client and update their access agents https://docs.connectwise.com/ScreenConnect_Documentation/Get_started/Host_page/Reinstall_and_upgrade_an_access_agent .; On-prem: Upgrade to ScreenConnect client version 26.6.5 or later.; Automate-integrated ScreenConnect deployments: Automate partners are eligible to update their integrated; on-premises ScreenConnect installation as long as their Automate Assurance; subscription is active. Automate partners should apply the ScreenConnect 26.6.5 update through Automate; Product Updates. | Update reference ↗ |
| CVE-2026-11596 | 10 Jun 2026 | All versions prior to 26.2 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2026-3564 | 17 Mar 2026 | All server versions prior to 26.1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-14823 | 18 Dec 2025 | ScreenConnect (all supported versions) when used with the Certificate Signing Extension versions prior to 1.0.12 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-14265 | 11 Dec 2025 | All versions prior to 2025.8 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2025-3935 | 25 Apr 2025 | ScreenConnect: <25.2.3 | Cloud: No action is required.; On-premises: Upgrade to the latest stable version.; Details and guidance can be found here:; ScreenConnect 25.2.4 Security Patch https://www.connectwise.com/company/trust/security-bulletins/screenconnect-security-patch-2025.4 | Update reference ↗ |
| CVE-2024-1709 | 21 Feb 2024 | ScreenConnect: ≤ 23.9.7 | The Cyber Centre strongly recommends that organizations patch any ScreenConnect systems immediately. ConnectWise recommends updating impacted products to version 23.9.8 Footnote 2 . The vendor states cloud partners are remediated against both vulnerabilities reported on February 19. Organizations should also review and implement the Cyber Centre’s Top 10 IT Security Actions Footnote 3 with an emphasis on the following topics: Consolidating, monitoring, and defending Internet gateways. Patching operating systems and applications. Isolate web-facing applications. Should activity matching the content of this alert be discovered, recipients are encouraged to report via the My Cyber Portal , or email contact@cyber.gc.ca . | Update reference ↗ |
| CVE-2024-1708 | 21 Feb 2024 | ScreenConnect: ≤ 23.9.7 | The Cyber Centre strongly recommends that organizations patch any ScreenConnect systems immediately. ConnectWise recommends updating impacted products to version 23.9.8 Footnote 2 . The vendor states cloud partners are remediated against both vulnerabilities reported on February 19. Organizations should also review and implement the Cyber Centre’s Top 10 IT Security Actions Footnote 3 with an emphasis on the following topics: Consolidating, monitoring, and defending Internet gateways. Patching operating systems and applications. Isolate web-facing applications. Should activity matching the content of this alert be discovered, recipients are encouraged to report via the My Cyber Portal , or email contact@cyber.gc.ca . | Update reference ↗ |
| CVE-2022-36781 | 28 Sep 2022 | 22.7 < 22.6* | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.