ScreenConnect Vulnerabilities: What MSP Customers Should Verify

Verify ScreenConnect hosting, version, exposure, patch evidence, user access, logs, and incident review against current ConnectWise bulletins.

Back to Blog
(Updated )
2 min read
Security operations center with analysts monitoring network alerts on large displays in a dark room with blue ambient lighting

ScreenConnect is privileged remote-access software, so customers should know which instance reaches their systems, who hosts it, which version is running, and how the provider handles security bulletins. A past patch does not establish current safety; evidence must be tied to the exact instance and date.

Current as of 2026-08-15

ConnectWise’s security bulletin center is the current vendor source. A 2025 bulletin addressed CVE-2025-3935 in versions 25.2.3 and earlier, while CISA separately lists the 2024 authentication bypass CVE-2024-1709 as known exploited.

Decision summary

  • Identify every hosted and self-hosted ScreenConnect instance with access to your environment.
  • Verify the exact version and vendor remediation evidence.
  • Review technicians, MFA, roles, sessions, audit logs, agents, extensions, and integrations.
  • Treat suspected exposure as an incident-response question, not only a patch task.

Two different vulnerability events

ConnectWise’s April 2025 bulletin describes CVE-2025-3935 and remediation for affected versions. CISA’s CVE-2024-1709 alert concerns an earlier authentication bypass in ScreenConnect 23.9.7 and prior. Do not merge their affected versions or remediation statements.

Questions for an MSP or internal owner

  • What is the exact instance URL, hosting model, owner, and version?
  • When was the relevant patch installed, and what verifies it?
  • Were hosted cloud and self-hosted instances treated differently?
  • Which users, roles, extensions, agents, and integrations exist?
  • Were audit logs and indicators reviewed for the vulnerable period?
  • What customer notification and containment criteria apply?

Patch and investigate

ConnectWise’s bulletin tells customers that suspect systems should follow incident-response procedures and be investigated before being returned to service. Patching closes the described vulnerability; it does not remove an attacker, unauthorized account, token, extension, or downstream persistence that may already exist.

Maintain a remote-access control record

Record instance inventory, version checks, bulletin subscriptions, identity controls, access reviews, log retention, emergency disablement, and exit procedures. Customers should be able to revoke provider access without losing their own administrative control.

Next step

Request a dated ScreenConnect evidence packet from every provider with remote access and reconcile it to your endpoint and server inventory. For an environment-specific baseline, request an ITECS technology and security assessment.

Primary Sources

Review trigger: Review every ConnectWise bulletin, instance or hosting change, provider change, unexplained account, or remote-access incident.

continue reading

More ITECS blog articles

Browse all articles

About ITECS Team

The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.

View full profile and articles

Share This Article

Continue Reading

Explore more insights and technology trends from ITECS

View All Articles