ConnectWise R1Soft becomes a soft target

Share This Post

On Oct. 28 ConnectWise released a critical security patch for a vulnerability that effects its R1Soft Server Backup Manager (SBM) and ConnectWise Recover v2.97 and earlier. The vulnerability could allow an attacker to access sensitive data or perform remote code execution. Hopefully you don’t have these exposed to the internet, but if you do – work to get that behind a VPN or similar.

While ConnectWise Recover SBMs were automatically updated, you need to upgrade the server backup manager to SBM v6.16.4. There is guidance on how to do this in the ConnectWise security bulletin posted below.

And speaking of backups, you have offline copies of those, right? Its crucial that you protect and have copies of your critical data and applications in a cyber incident, like ransomware.

References:

https://www.connectwise.com/company/trust/security-bulletins/r1soft-and-recover-security-bulletin

https://www.bleepingcomputer.com/news/security/connectwise-fixes-rce-bug-exposing-thousands-of-servers-to-attacks/



Reach out to our incident response team for help

More To Explore

Information Security News 3-9-2026

Experts Warn Iran-Linked Hacktivists Could Target Governments Article Link: https://www.nextgov.com/cybersecurity/2026/03/iran-linked-hacktivists-could-target-governments-experts-warn/411876/ Iran-Linked MuddyWater Hackers Target U.S. Networks with New Dindoor Backdoor Article Link: https://thehackernews.com/2026/03/iran-linked-muddywater-hackers-target.html Indian APT

Information Security News – 3/2/2026

CrowdStrike: Average Cyberattack Breakout Time Now Under 30 Minutes Article Link: https://www.scworld.com/news/crowdstrike-average-cyberattack-breakout-time-now-under-30-minutes Critical Cisco SD-WAN Bug Exploited in Zero-day Attacks Since 2023 Article Link: https://www.bleepingcomputer.com/news/security/critical-cisco-sd-wan-bug-exploited-in-zero-day-attacks-since-2023/

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.