Database/Control plane, storage & DevOps

ConnectWise ScreenConnect: ViewState code injection
CVSS 8.1CVE-2025-3935Control plane, storage & DevOpsKnown exploitedcurated
Impact
ViewState code injection -> RCE once ASP.NET machine keys are obtained
Who can reach it
Network (remote)
What to do
Control-plane: patch + rotate ASP.NET machine keys
References
Related entries
- ConnectWise ScreenConnect: Auth bypass via alternate pathCVE-2024-1709 · ConnectWise ScreenConnectCritical
- ConnectWise ScreenConnect: Path traversal enabling remote code executionCVE-2024-1708 · ConnectWise ScreenConnectHigh
- MinIO (service accounts / STS session policies): The session policy attached to a service account or STS credential isCVE-2025-62506 · MinIO (service accounts / STS session policies)High
- Apache CloudStack: MinIO policies survive bucket deletion, giving a former owner access to a new bucket of the same nameCVE-2025-66467 · Apache CloudStack (MinIO object store policy cleanup on bucket deletion)High
- N-able N-central: Incomplete patch for CVE-2026-18556CVE-2026-18577 · N-able N-centralHigh
- VMware Aria Operations (command injection during assisted migration): An unauthenticated attacker injects commandsCVE-2026-22719 · VMware Aria Operations (command injection during assisted migration)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.