CISA Alert: Hackers Actively Exploiting ConnectWise ScreenConnect Vulnerability for Remote Code Execution


# CISA Warns of Active Exploitation of ScreenConnect and Other Critical Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to federal agencies regarding active exploitation of several critical security vulnerabilities, including a recently patched flaw in ConnectWise ScreenConnect.

## ScreenConnect Vulnerability Under Active Attack

CISA reports that threat actors are actively exploiting CVE-2025-3935, a vulnerability in ConnectWise ScreenConnect that could enable remote code execution on affected servers. ConnectWise patched this issue on April 24, describing it as a ViewState code injection vulnerability.

The flaw affects ASP.NET Web Forms, where attackers with privileged access who compromise machine keys can execute malicious code on the server. While some customers have suggested a connection between this vulnerability and a recent ConnectWise breach (suspected to be state-sponsored), the company has not confirmed the attack vector. Reports indicate only “a very small number” of ScreenConnect customers were affected.

## Additional Critical Vulnerabilities Being Exploited

CISA’s alert also highlighted four other actively exploited vulnerabilities:

– **CVE-2021-32030** (Critical, 9.8): Authentication bypass in ASUS GT-AC2900 and Lyra Mini routers
– **CVE-2023-39780** (High, 8.8): OS injection in ASUS RT-AX55 routers (requires authentication)
– **CVE-2024-56145** (Critical, 9.3): Code injection in Craft CMS that can lead to remote code execution
– **CVE-2025-35939** (Medium, 6.9): Allows unauthenticated clients to introduce PHP code to known file locations on Craft CMS servers

Security researchers at GreyNoise have reported that the ASUS RT-AX55 vulnerability has been exploited in recent months by what appears to be “a well-resourced and highly capable adversary.” Attackers have chained CVE-2023-39780 with undocumented authentication bypass techniques to create a botnet called AyySSHush.

All five vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog. Federal agencies are required to implement vendor-recommended mitigations or discontinue using the affected products by June 23.

Share This Article