AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-14265

CRITICAL · CVSS 9.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-12-11 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.1. See the original NVD description below for full technical details.

CVE
CVE-2025-14265
Severity
CRITICAL
CVSS
9.1
EPSS
0.34%

Original NVD Description

In versions of ScreenConnectâ„¢ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or arbitrary extensions by authorized or administrative users. Abuse of this behavior could result in the execution of custom code on the server or unauthorized access to application configuration data. This issue affects only the ScreenConnect server component; host and guest clients are not impacted. ScreenConnect 25.8 introduces enhanced server-side configuration handling and integrity checks to ensure only trusted extensions can be installed.

Related CVEs

Other vulnerabilities affecting the same vendor(s)