logo

Critical Vulnerability Disclosure: ConnectWise/R1Soft Server Backup Manager Remote Code Execution & Supply Chain Risks

ID: 3276de59-32b0-50ff-8e3e-32bf46a3f2b6

STIX ID: report--3276de59-32b0-50ff-8e3e-32bf46a3f2b6

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2024-02-24

Date Updated: 2026-04-28

...
...

Huntress researchers reproduced an authentication bypass in the ZK framework (CVE-2022-36537) present in ConnectWise R1Soft Server Backup Manager, developed a chained exploit that uploads a malicious JDBC driver to obtain root remote code execution, and demonstrated the ability to push LockBit 3.0 ransomware to downstream endpoints; ConnectWise released a patch (SBM v6.16.4) which Huntress validated, while research highlights thousands of potentially exposed instances and provides indicators and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.