"ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation," CISA said.
CISA: active exploitation and an urgent federal order
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) says attackers are exploiting a critical-severity missing-authorization flaw in ConnectWise ScreenConnect "in the wild." CISA added the vulnerability to its catalog of actively exploited flaws on Friday and ordered U.S. federal agencies to secure affected systems within three days, underscoring that the vulnerability poses "significant risks to the federal enterprise."
What ConnectWise has advised and the specific mitigation
ConnectWise shared temporary mitigation measures on September 7, advising security teams to disable TransferFiles permissions to block potential attacks. The mitigation is presented as a stopgap while organizations secure and patch. The company has a history of addressing ScreenConnect flaws: in March it fixed a cryptographic signature verification vulnerability tracked as CVE-2026-3564, and last year it "rotated digital a limited number of customers" according to the public record.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadHow many systems remain exposed — Shadowserver's tally
Internet threat watchdog Shadowserver now tracks over 1,000 ScreenConnect instances that remain unpatched and exposed online. The majority are in North America (758), followed by Europe (180). Those exposed systems represent immediate targets for attackers who can chain an authorization bypass or privilege-management flaw into file transfer and remote execution across active sessions.
Who has exploited ScreenConnect before — Kimsuky, ransomware gangs, and patterns
CISA notes that ScreenConnect vulnerabilities are frequently targeted by both financially motivated and state-backed groups. The advisory references prior abuse: the Korean-backed Kimsuky hacking group and several ransomware gangs exploited another ScreenConnect flaw, CVE-2024-1709, in 2024. CISA also reports that since 2024 it has flagged four ScreenConnect security issues as actively exploited, and that two of those have been abused in ransomware attacks.
What this means for federal agencies, MSPs, and security teams
- U.S. federal agencies: CISA's three-day directive creates an immediate compliance window. Agencies must prioritize discovery of ScreenConnect instances and apply CISA-recommended mitigations and patches within the timeframe set by the agency.
- Managed service providers and ConnectWise customers: ConnectWise provides services to more than 100,000 IT providers worldwide, and many MSPs and IT teams use ScreenConnect for troubleshooting, patching, and maintenance. Those organizations will need to assess remote-support deployments, disable TransferFiles where advised, and confirm whether servers or endpoints are exposed to the internet.
- Security teams and defenders: The combination of active exploitation, known exposed instances tracked by Shadowserver, and past abuse by both state-backed and financially motivated actors raises the priority of this vulnerability. Defenders should follow the temporary mitigations published by ConnectWise while validating patch status across devices.
The record in this advisory is straightforward: a critical authorization and privilege-management flaw in a widely used remote support product is being exploited, CISA has escalated the risk to federal agencies, and more than a thousand internet-connected instances remain exposed. The practical questions now are whether organizations will act fast enough to apply the temporary mitigations and patches, and whether defenders can close the window that attackers are already using.
Read the original advisory: https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/



