# ConnectWise vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-10, Threadlinqs tracks 6 ConnectWise CVEs, 4 in the CISA Known Exploited Vulnerabilities catalog, 2 used in ransomware campaigns, linked to 39 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-10

## Exploitation timeline

Threadlinqs has recorded 6 ConnectWise CVEs published between 2024-02-15 and 2026-09-15. The busiest month was 2024-02 (2 new CVEs). 4 of them (67%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 6 of 6 tracked ConnectWise CVEs.

- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709) — CRITICAL 10 · KEV · Ransomware · EPSS 100% · 2024-02-21
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708) — HIGH 8.4 · KEV · Ransomware · EPSS 95.4% · 2024-02-21
- [CVE-2025-3935](https://intel.threadlinqs.com/cve/CVE-2025-3935) — HIGH 8.1 · KEV · EPSS 3.5% · 2025-04-25
- [CVE-2026-84869](https://intel.threadlinqs.com/cve/CVE-2026-84869) — CRITICAL 9.9 · KEV · EPSS 0.7% · 2026-09-08
- [CVE-2025-14265](https://intel.threadlinqs.com/cve/CVE-2025-14265) — CRITICAL 9.1 · EPSS 0.4% · 2025-12-11
- [CVE-2026-9089](https://intel.threadlinqs.com/cve/CVE-2026-9089) — HIGH 8.8 · EPSS 0.2% · 2026-05-21

## Products affected

Threadlinqs normalises CPE and CNA product records across all 6 CVEs; 2 distinct ConnectWise products are affected. The most frequently affected:

- ScreenConnect — 5 CVEs
- Automate — 1 CVE

## Threat activity

39 tracked threat campaigns reference ConnectWise products or exploit ConnectWise CVEs; the 25 most recent are listed.

- [Healthcare Sector Ransomware Targeting and Expanding Attack Surface (Qilin, Akira, DragonForce, LockBit, The Gentlemen)](https://intel.threadlinqs.com/threat/TL-2026-3127) — HIGH — 2026-10-09
- [Q3 2026 Record Ransomware Surge: 2,627 Claimed Attacks, Qilin and The Gentlemen Lead, Clop Resurgence via PTC Windchill CVE-2026-12569](https://intel.threadlinqs.com/threat/TL-2026-3135) — HIGH — 2026-10-09
- [Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue ScreenConnect RMMs](https://intel.threadlinqs.com/threat/TL-2026-2998) — HIGH — 2026-10-07
- [Phishing Campaign Abuses Legitimate ScreenConnect Client for Remote Access via Fake Payment Notification](https://intel.threadlinqs.com/threat/TL-2026-2931) — MEDIUM — 2026-10-05
- [ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing](https://intel.threadlinqs.com/threat/TL-2026-2826) — MEDIUM — 2026-10-01
- [RMM tools distributed via phishing: ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud and N-able abused for remote access](https://intel.threadlinqs.com/threat/TL-2026-3037) — HIGH — 2026-10-01
- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations](https://intel.threadlinqs.com/threat/TL-2026-2802) — HIGH — 2026-09-30
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — HIGH — 2026-09-29
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — HIGH — 2026-09-27
- [Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by Initial Access Brokers](https://intel.threadlinqs.com/threat/TL-2026-2645) — HIGH — 2026-09-25
- [CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-2533) — CRITICAL — 2026-09-16
- [ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Lure](https://intel.threadlinqs.com/threat/TL-2026-2594) — MEDIUM — 2026-09-14
- [Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Access](https://intel.threadlinqs.com/threat/TL-2026-2453) — HIGH — 2026-09-09
- [Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2372) — HIGH — 2026-09-07
- [US-First RMM Phishing Campaign Spans 46 Countries via Disposable Vercel/Netlify Infrastructure and Password-Protected VBS-to-PowerShell Delivery](https://intel.threadlinqs.com/threat/TL-2026-2308) — HIGH — 2026-09-03
- [BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target Financial-Sector CEOs via Browser-in-the-Middle](https://intel.threadlinqs.com/threat/TL-2026-2315) — HIGH — 2026-09-03
- [SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1880) — HIGH — 2026-08-04
- [Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto, SimpleHelp, N-able, and Heartbeat RM](https://intel.threadlinqs.com/threat/TL-2026-1820) — MEDIUM — 2026-08-02
- [Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)](https://intel.threadlinqs.com/threat/TL-2026-1732) — HIGH — 2026-07-27
- [MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign](https://intel.threadlinqs.com/threat/TL-2026-1530) — HIGH — 2026-07-19
- [AsyncRAT Campaign Uses DLL Sideloading and ScreenConnect for Stealthy Remote Access (SEO-Poisoned Fake Installer Sites)](https://intel.threadlinqs.com/threat/TL-2026-1081) — HIGH — 2026-07-02
- [ScreenConnect Masked as Freeware: Large-Scale AsyncRAT Distribution Campaign via SEO-Poisoned Fake Software Sites](https://intel.threadlinqs.com/threat/TL-2026-1040) — HIGH — 2026-07-01
- [Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprinting](https://intel.threadlinqs.com/threat/TL-2026-1126) — HIGH — 2026-07-01
- [The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to Deliver ConnectWise ScreenConnect RMM Access](https://intel.threadlinqs.com/threat/TL-2026-0805) — HIGH — 2026-06-15
- [RatPressto Phishing Kit — Fake Adobe Document Cloud Pages Deliver ConnectWise ScreenConnect RAT](https://intel.threadlinqs.com/threat/TL-2026-0629) — MEDIUM — 2026-05-29

## Threat actors targeting ConnectWise

Named threat actors attributed to campaigns that involve ConnectWise products or CVEs, with the number of linked campaigns:

- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 2 campaigns
- [Storm-1175](https://intel.threadlinqs.com/actor/Storm-1175) — 2 campaigns
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 2 campaigns
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1 campaign
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1 campaign
- [APT35](https://intel.threadlinqs.com/actor/APT35) — 1 campaign
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1 campaign
- [APT42](https://intel.threadlinqs.com/actor/APT42) — 1 campaign
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1 campaign
- [Clop](https://intel.threadlinqs.com/actor/Clop) — 1 campaign
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 1 campaign
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1 campaign

## How to prioritise ConnectWise patching

This order follows the data Threadlinqs holds for ConnectWise, not a generic severity checklist:

- 4 of 6 ConnectWise CVEs (67%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709), [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708), [CVE-2025-3935](https://intel.threadlinqs.com/cve/CVE-2025-3935).
- 2 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2025-14265](https://intel.threadlinqs.com/cve/CVE-2025-14265) (0.4%), [CVE-2026-9089](https://intel.threadlinqs.com/cve/CVE-2026-9089) (0.2%).
- 3 CVEs score Critical and 3 High on CVSS v3 (maximum 10, average 9.1); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-10 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/connectwise
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
