PSA and RMM

Solve any challenge with one platform

Operate more efficiently, reduce complexity, improve EBITDA, and much more with the purpose-built platform for MSPs.

Cybersecurity and Data Protection

Ensure security and business continuity, 24/7

Protect and defend what matters most to your clients and stakeholders with ConnectWise's best-in-class cybersecurity and BCDR solutions.

Automation and Integrations

Integrate and automate to unlock cost savings

Leverage generative AI and RPA workflows to simplify and streamline the most time-consuming parts of IT.

University

University Log-In

Check out our online learning platform, designed to help IT service providers get the most out of ConnectWise products and services.

About Us

Experience the ConnectWise Way

Join hundreds of thousands of IT professionals benefiting from and contributing to a legacy of industry leadership when you become a part of the ConnectWise community.

News and Press

Experience the ConnectWise Way

Join hundreds of thousands of IT professionals benefiting from and contributing to a legacy of industry leadership when you become a part of the ConnectWise community.

ConnectWise

ScreenConnect 25.8 Security Patch

Date: 12/11/2025

Products: ScreenConnect
Severity: Important
Priority: 2 – Moderate

Summary

ConnectWise has released a security update for ScreenConnect™ that addresses issues which could allow unauthorized access to configuration data or the installation of untrusted extensions under specific conditions. There is no evidence of exploitation, and these issues require authorized or administrative-level access to be leveraged. These issues affect only the ScreenConnect server component; host and guest clients are not impacted. The ScreenConnect 25.8 patch strengthens server-side validation, enforces integrity checks for extension installations, and enhances overall platform security and stability.

The ScreenConnect 25.8 patch strengthens server-side validation, enforces integrity checks for extension installations, and enhances overall platform security and stability.

Vulnerability

CVE-2025-14265

CWE ID Description Base Score Vector
CWE-494 Download of Code
Without Integrity Check
9.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Severity

Important — Vulnerabilities that could compromise confidential data or other resources but require additional access, privilege or circumstances to do so.

Priority

2 – Moderate — Vulnerabilities that have elevated risk but exploits are neither known nor anticipated to be imminent. Recommend updates be prioritized against normal change management timelines but no longer than 30 days.

Affected Versions

ScreenConnect versions prior to 25.8 are impacted.

Remediation

Cloud
No action is required. ScreenConnect servers hosted in “screenconnect.com” cloud (standalone and Automate/RMM integrated) or “hostedrmm.com” for Automate partners have been updated to remediate the issue.

On-prem
ScreenConnect Partners:
Please upgrade to ScreenConnect version 25.8 and update your guest clients to the same version. Visit Download | ScreenConnect page to download and apply the update (access requires a valid on-premises license).

Automate On-Prem Partners with ScreenConnect Integration:

For partners using an on-premises ScreenConnect installation integrated with Automate, please follow these steps to ensure a smooth upgrade to ScreenConnect 25.8:

  1. If applicable, confirm that the Automate ScreenConnect Extension is updated to version 4.4.0.16.
  2. If the extension is not yet at 4.4.0.16, allow it to auto-update or apply the update from the Extensions tab.
  3. Once the extension is confirmed to be on 4.4.0.16, you may safely upgrade the ScreenConnect server to version 25.8. Visit the Automate Product Updates page to download and apply the ScreenConnect 25.8 update