Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical ScreenConnect Vulnerability Let Attackers Expose Sensitive Configuration Data

Critical ScreenConnect Vulnerability Let Attackers Expose Sensitive Configuration Data

Posted on December 16, 2025December 16, 2025 By CWS

ConnectWise has issued a safety replace for ScreenConnect™ to deal with a essential vulnerability that might allow attackers to reveal delicate configuration information and set up untrusted extensions.

The flaw, recognized as CVE-2025-14265, impacts solely the ScreenConnect server part, leaving host and visitor purchasers unaffected.

The vulnerability stems from improper code integrity validation throughout extension installations, categorized beneath CWE-494 (Obtain of Code With out Integrity Test).

With a CVSS 3.1 base rating of 9.1, CVE-2025-14265 falls into the “Necessary” severity class. Indicating potential compromise of confidential information or sources beneath particular situations.

CVE IDCWE IDDescriptionBase ScoreCVE-2025-14265CWE-494Download of Code With out Integrity Check9.1

Exploitation requires licensed or administrative-level entry, and ConnectWise has confirmed that there isn’t a proof of energetic exploitation within the wild.

Nevertheless, the vulnerability’s essential ranking and network-based assault vector (AV: N) underscore the significance of instant remediation.

The ScreenConnect 25.8 patch strengthens server-side validation, enforces integrity checks for extension installations, and enhances total platform safety.

All variations of ScreenConnect earlier than 25.8 are affected and require an instantaneous replace. For cloud-hosted installations on screenconnect.com or hostedrmm.com, updates have been mechanically utilized.

On-premises companions should improve to ScreenConnect model 25.8 and replace visitor purchasers accordingly.

Companions with Automate integration ought to first affirm their Automate ScreenConnect Extension is up to date to model 4.4.0.16 earlier than upgrading to ScreenConnect 25.8.

ConnectWise assigns this vulnerability a Precedence 2 – Reasonable ranking and recommends updating it inside 30 days by way of regular change administration processes.

Organizations ought to prioritize patching to forestall potential unauthorized entry to delicate configuration information and keep a safe distant entry infrastructure.

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Attackers, Configuration, Critical, Data, Expose, ScreenConnect, Sensitive, Vulnerability

Post navigation

Previous Post: JumpCloud Remote Assist Vulnerability Can Expose Systems to Takeover
Next Post: Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure

Related Posts

Malware Found in Top OpenClaw Skill Exposes Major Security Flaws Malware Found in Top OpenClaw Skill Exposes Major Security Flaws Cyber Security News
Vulnerability in Tenda Routers Allows Full Admin Access Vulnerability in Tenda Routers Allows Full Admin Access Cyber Security News
DragonForce Ransomware Claimed To Compromise Over 120 Victims in The Past Year DragonForce Ransomware Claimed To Compromise Over 120 Victims in The Past Year Cyber Security News
Microsoft Teams Enhances Security with Bot Blocking Microsoft Teams Enhances Security with Bot Blocking Cyber Security News
VECT and TeamPCP: Unveiling the Ransomware Supply Chain Strategy VECT and TeamPCP: Unveiling the Ransomware Supply Chain Strategy Cyber Security News
Hackers Using CastleRAT Malware to Attack Windows Systems and Gain Remote Access Hackers Using CastleRAT Malware to Attack Windows Systems and Gain Remote Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update
  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update
  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark