<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel xmlns:atom="http://www.w3.org/2005/Atom">
    <title>Security Bulletins</title>
    <link>https://www.connectwise.com/company/trust/security-bulletins</link>
    <description />
    <language>en-US</language>
    <copyright>Ⓒ ConnectWise 2025, LLC. All rights reserved.</copyright>
    <lastBuildDate>Mon, 24 Nov 2025 11:20:28 Z</lastBuildDate>
    <atom:link href="https://www.connectwise.com/company/trust/security-bulletins" rel="self" type="application/rss+xml" />
    <item>
      <guid isPermaLink="false">fabddea0-6025-4817-bca1-5fa3929f020a</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-spi-vulnerability</link>
      <title>ConnectWise Automate API Vulnerability</title>
      <description>&lt;p&gt;ConnectWise is aware of a vulnerability in a ConnectWise Automate API that could potentially allow a remote user to execute modifications within an individual Automate instance. This affects on-premise and cloud based versions of the product.&lt;/p&gt;</description>
      <pubDate>Tue, 09 Jun 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">3e0bd745-2206-40a0-bf1c-1bc94eebb179</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2020-06-12-update-connectwise-automate-api-vulnerability</link>
      <title>UPDATE - ConnectWise Automate API Vulnerability</title>
      <description>&lt;p&gt;&lt;span&gt;This is an update to our previous message noting the hotfix application to address the security vulnerability issue that was communicated on June 10, 2020. ConnectWise has identified a need for additional hardening measures to be applied to the hotfixes and are currently working to update the fixes accordingly. Updates are expected later today, but we recommend all Automate partners take the following actions listed below.&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 11 Jun 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">9e57f3fe-8bdb-4303-b595-d2e6c69bee9b</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2020-06-13-update-connectwise-automate-api-vulnerability</link>
      <title>UPDATE - ConnectWise Automate API Vulnerability</title>
      <description>&lt;p&gt;&lt;span&gt;This is an update to our previous message noting the hotfix application to address the security vulnerability issue that was communicated on June 12, 2020 and June 10, 2020. ConnectWise identified a need for additional hardening measures to be applied to the hotfixes and these new hotfixes are now available.&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 12 Jun 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">9b8101d8-2d84-4767-8c86-42ca6e43899d</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2020-06-22-connectwise-security-bulletin-new-customer-portal</link>
      <title>ConnectWise Security Bulletin - New Customer Portal</title>
      <description>&lt;p&gt;ConnectWise is aware of a vulnerability in the New Customer Portal that could potentially allow a remote user to execute modifications within an individual environment. This issue was responsibly disclosed by trusted advisors. There have been no reports of exploitation.&lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">4dbfcaf9-d3a2-4ee6-a251-82755c3ed02c</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2020-06-22-connectwise-security-bulletin-new-customer-portal_2</link>
      <title>ConnectWise Security Bulletin - New Customer Portal</title>
      <description>&lt;p&gt;ConnectWise is aware of a vulnerability in the New Customer Portal that could potentially allow an authenticated user access to that individual Administrative portal tenant. This issue was discovered internally. There has been no indication of exploitation.&lt;/p&gt;</description>
      <pubDate>Sun, 21 Jun 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">3092a40a-81c5-47d6-a6db-e8f96ca84744</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-control-host-header-injection</link>
      <title>ConnectWise Control Host Header Injection</title>
      <pubDate>Tue, 15 Dec 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">342f7a44-a8dc-446b-82be-b35f8a9073ca</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-multiple-security-fixes</link>
      <title>ConnectWise Automate Multiple Security Fixes</title>
      <pubDate>Thu, 21 Jan 2021 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">a5b14ab1-30b0-4ddb-bb4f-0dec85f53f54</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-improper-authentication</link>
      <title>ConnectWise Automate Improper Authentication</title>
      <pubDate>Wed, 07 Apr 2021 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">874303d8-6e4c-483a-b146-0ce6e6877182</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-improper-neutralization-of-special-elements</link>
      <title>ConnectWise Automate Improper Neutralization of Special Elements</title>
      <pubDate>Mon, 10 May 2021 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">f29c3b7a-df8f-4b49-acb7-0710c36c7b81</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2021-06-18---connectwise-automate-improper-restriction-of-xml-external-entity-reference</link>
      <title>ConnectWise Automate Improper Restriction of XML External Entity Reference</title>
      <pubDate>Thu, 17 Jun 2021 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">b19b860a-9e24-498c-80df-d63c162ac795</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2021-07-06-updated-trust-site---reset-of-rss-feed</link>
      <title>July 6, 2021 - Updated Trust Site &amp; Resetting of RSS Feed</title>
      <pubDate>Mon, 05 Jul 2021 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">a309990c-5976-4d2b-8cf6-b2a534d76d60</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-plugin-insufficiently-protected-credentials</link>
      <title>ConnectWise Automate Plugin Insufficiently Protected Credentials</title>
      <pubDate>Tue, 16 Nov 2021 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">20adc636-69ed-448e-b1a4-e6ff40442643</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/partner-infosec-hotline-unavailablealternate-communication-mechanism</link>
      <title>Partner InfoSec Hotline Unavailable/Alternate Communication Mechanism</title>
      <pubDate>Thu, 07 Apr 2022 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">9c2b457b-7b6a-4f3f-a465-4ebef4bfa867</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-protection-mechanism-failure</link>
      <title>ConnectWise Automate: Protection Mechanism Failure</title>
      <pubDate>Wed, 13 Jul 2022 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">2cdf7020-297e-4071-989d-e3c7907fb017</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2022-8-security-fix</link>
      <title>ConnectWise Automate 2022.8 Security Fix</title>
      <description>&lt;p&gt;ConnectWise Automate versions 2022.7 and earlier are impacted. &amp;nbsp;&lt;/p&gt;</description>
      <pubDate>Wed, 03 Aug 2022 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">9ba80ab7-8a9b-4110-8563-11399c1741c8</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2022-9-security-fix</link>
      <title>ConnectWise Automate 2022.9 Security Fix </title>
      <description>&lt;p&gt;ConnectWise Automate versions 2022.8 and earlier are impacted.&lt;/p&gt;</description>
      <pubDate>Wed, 07 Sep 2022 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">67e1597e-372d-45f1-8f64-296991c94b49</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8</link>
      <title>ConnectWise ScreenConnect 23.9.8 security fix</title>
      <description>&lt;p&gt;&lt;span&gt;ConnectWise ScreenConnect&amp;trade; versions 23.9.7 and earlier are impacted.&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Sun, 18 Feb 2024 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">224c84e9-8a25-40b1-a597-fa64d510b908</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2020-07-16-connectwise-authentication-bypass</link>
      <title>ConnectWise Authentication Bypass</title>
      <description>&lt;p&gt;&lt;span&gt;A vulnerability exists in a ConnectWise Automate API that could potentially allow a remote user to execute modifications within an individual Automate instance. This affects on-premise and cloud based versions of the product.&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 15 Jul 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">84283949-5243-4a47-b234-efa8e45eb9b3</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2022.11-security-fix</link>
      <title>ConnectWise Automate 2022.11 Security Fix</title>
      <description>&lt;p&gt;ConnectWise Automate versions 2022.10 and earlier are impacted.&lt;/p&gt;</description>
      <pubDate>Wed, 02 Nov 2022 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">04957cf8-d890-4862-9855-5da4330f14d2</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2023.1-security-bulletin</link>
      <title>ConnectWise Automate 2023.1 Security Fix</title>
      <description>&lt;p&gt;ConnectWise Automate versions 2022.12 and earlier are impacted.&lt;/p&gt;</description>
      <pubDate>Fri, 20 Jan 2023 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">1a5aa11e-dc88-475a-bdbf-b305ad2246eb</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2023.5-security-bulletin</link>
      <title>ConnectWise Automate 2023.5 Security Fix</title>
      <description>&lt;p&gt;Pull from blurb within card on /company/trust/security-bulletins&lt;/p&gt;</description>
      <pubDate>Wed, 10 May 2023 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">e35762fe-58a3-460e-a924-4f05dca68852</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2024.3-security-fix</link>
      <title>ConnectWise Automate 2024.3 security fix</title>
      <description>&lt;p&gt;ConnectWise Automate server version 2024.2 and earlier versions have been identified as vulnerable to blind SQL injection (time-based) within the API.&lt;/p&gt;</description>
      <pubDate>Thu, 14 Mar 2024 04:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">5596bdbd-97fc-4dca-9bb7-0ca639ecd3a9</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2025.9-security-fix</link>
      <title>Security Bulletin | Automate Security Fix 2025.9</title>
      <description>&lt;p&gt;&lt;span class="NormalTextRun SCXW197821906 BCX8" data-ccp-parastyle="No Spacing"&gt;ConnectWise has released a security update for ConnectWise Automate addressing vulnerabilities that could expose agent communications and updates to interception or tampering if &lt;/span&gt;&lt;span class="NormalTextRun SCXW197821906 BCX8" data-ccp-parastyle="No Spacing"&gt;certain&lt;/span&gt;&lt;span class="NormalTextRun SCXW197821906 BCX8" data-ccp-parastyle="No Spacing"&gt; configurations are used.&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 16 Oct 2025 04:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">ad1695d3-8a1a-4070-9564-cb94f8671e3a</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2020-07-16-connectwise-automate-api-vulnerability</link>
      <title>ConnectWise Automate API Vulnerability</title>
      <description>&lt;p&gt;A vulnerability exists in a ConnectWise Automate API that could potentially allow a remote user to execute arbitrary SQL statements against an individual Automate instance. This affects on-premise and cloud based versions of the product.&lt;/p&gt;</description>
      <pubDate>Wed, 15 Jul 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">9c9cb2ec-fa52-472d-8252-f6b5483648ae</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwiseautomatenetwork-probe-insufficientlyprotectedcredentials</link>
      <title>ConnectWise Automate: Network Probe Insufficiently Protected Credentials</title>
      <pubDate>Wed, 11 May 2022 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">f0d17ca5-7a35-46cc-add5-8ac0bcb48337</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2022-06-23-connectwise-automate-security-fixes</link>
      <title>ConnectWise Automate: Security Fixes</title>
      <pubDate>Wed, 22 Jun 2022 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">43c47b17-382c-44ca-9877-6126c0ebf14d</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/r1soft-and-recover-security-bulletin</link>
      <title>ConnectWise BCDR and R1Soft Server Backup Manager Critical Security Release</title>
      <description>&lt;p&gt;ConnectWise BCDR (formerly Recover): Recover v2.9.7 and earlier versions are impacted. R1Soft: SBM v6.16.3 and earlier versions are impacted.&lt;/p&gt;</description>
      <pubDate>Thu, 27 Oct 2022 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">9f2bce7d-4605-4d9c-96b2-fc0876dea143</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2021-06-15---connectwise-control-broken-access-control</link>
      <title>ConnectWise Control Broken Access Control</title>
      <pubDate>Mon, 14 Jun 2021 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">689298e9-11e3-40ce-8f39-c07aef148796</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2020-08-20-connectwise-control-improper-authentication</link>
      <title>ConnectWise Control Improper Authentication</title>
      <pubDate>Wed, 19 Aug 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">c051d4bd-5bc8-4175-98b3-c9bff90b603d</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-psa-2022.2</link>
      <title>ConnectWise PSA 2022.2 Security Fix</title>
      <description>&lt;p&gt;&lt;span&gt;ConnectWise PSA&amp;trade; versions 2022.2 and earlier are impacted.&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 11 Oct 2023 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">da052ce6-1fd8-4381-822f-fd9e8b120436</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-psa-2025.9-security-fix</link>
      <title>ConnectWise PSA 2025.9 Security Fix</title>
      <description>&lt;p&gt;&lt;span&gt;In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sensitive user information. Please see the bulletin for more information.&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 09 Jul 2025 04:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">d630bd75-03cb-4635-afd6-3efc98f7aee6</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.8-security-fix</link>
      <title>ConnectWise ScreenConnect 23.8 Security Fix</title>
      <description>&lt;p&gt;ConnectWise ScreenConnect, ConnectWise Automate (cloud instances only where ScreenConnect is installed)&lt;/p&gt;</description>
      <pubDate>Sun, 19 Nov 2023 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">110b628f-6f03-4a1c-9eb5-091b7c347738</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2020-07-02-connectwise-security-bulletin-connectwise-control-phishing-issue</link>
      <title>ConnectWise Security Bulletin - ConnectWise Control Phishing Issue</title>
      <description>&lt;p&gt;&lt;span&gt;Several reports have been received that a number of partners have received phishing emails purporting to take the partner to a fake Control login page and asking for credentials.&lt;/span&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 01 Jul 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">6f5e3429-849e-4b60-98ee-e64a2c02847c</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/2020-10-31-connectwise-security-public-service-announcement</link>
      <title>ConnectWise Security: Public Service Announcement</title>
      <pubDate>Fri, 30 Oct 2020 16:00:00 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">65f1e96a-1b87-41e0-b80a-3e79f6113bcf</guid>
      <link>https://www.connectwise.com/company/trust/security-bulletins/screenconnect-security-patch-2025.4</link>
      <title>ScreenConnect 25.2.4 Security Patch</title>
      <description>&lt;p&gt;ScreenConnect versions 25.2.3 and earlier are impacted. Please see the following bulletin for more information.&lt;/p&gt;</description>
      <pubDate>Thu, 24 Apr 2025 04:00:00 Z</pubDate>
    </item>
  </channel>
</rss>