Skip to main content
CybersecurityVulnerability Management

ConnectWise Discloses New ScreenConnect Flaw, Offers Mitigations

Empty remote access support workstation with laptop and monitor on a clean desk in a typical office setting.

"ConnectWise has identified an issue affecting file transfer behavior in ScreenConnect® Remote Access Support and Access sessions," the company said in a security advisory issued on Thursday.

The advisory describes a newly discovered vulnerability in ScreenConnect — the remote access platform used by managed service providers (MSPs), IT departments, and support teams — that affects both cloud-hosted and on-premises deployments. ConnectWise says it will issue a permanent fix later this week, but until that patch arrives it has published step-by-step mitigations administrators must apply manually.

ConnectWise advisory and temporary mitigations

ConnectWise classified the problem as an issue with file transfer behavior inside Support and Access sessions. The company has not assigned a CVE identifier for the flaw, and the permanent patch remains pending.

Until the update is available, ConnectWise asks administrators to follow these steps in the ScreenConnect Administration interface to block potential misuse of file transfers:

  • Log in to the ScreenConnect Administration page.
  • Go to Administration > Security > Roles.
  • Edit user roles and check session groups with permissions assigned to them.
  • In the Scoped Permissions window, deselect the TransferFiles permission (or TransferFilesInSession for legacy) for each session group.
  • Save changes and repeat for all roles.

ConnectWise frames these measures as temporary mitigations designed to reduce attack surface until the forthcoming patch is released.

Scope: cloud and on-premises ScreenConnect instances

The vulnerability is reported to affect both cloud and on-premises instances of ScreenConnect. The product is commonly embedded in MSP workflows for troubleshooting, patching, and system maintenance, making the reach of any flaw potentially broad across service-provider customer bases and enterprise IT departments.

Exposure: Shadowserver tracking and the active threat history

Internet security watchdog Shadowserver currently tracks nearly 6,000 ScreenConnect instances exposed online. The advisory notes there is no public information about how many of those instances are honeypots or have already been secured.

The history of ScreenConnect flaws underscores risk for exposed systems. In 2024, ransomware gangs and the Kimsuky North Korean APT exploited a different ScreenConnect flaw tracked as CVE-2024-1709 to drop malware on vulnerable systems. Last year, ConnectWise disclosed that suspected state-sponsored hackers breached its systems via a high-severity ViewState code injection bug (CVE-2025-3935) and gained access to some cloud-based customer instances. Earlier this year, ConnectWise addressed a ScreenConnect cryptographic signature verification vulnerability tracked as CVE-2026-3564 that could allow attackers to hijack unpatched instances.

Since February 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three ScreenConnect vulnerabilities to its catalog of actively exploited flaws, two of which were also abused in ransomware attacks — a reflection of both frequency and severity in the threat environment surrounding this product family.

What this means for MSPs, IT teams, and CISA

  • MSPs and IT teams: The advisory requires hands-on role and permission reviews across all ScreenConnect roles and session groups. Because the mitigation must be applied role-by-role, administrators should prioritize accounts and session groups that permit broad support access.
  • Security teams: The Blue Report 2026 observation is directly relevant here: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The report measures defenses technique by technique across 338 million simulations, underscoring the practical risk when legitimate remote-access paths are abused.
  • CISA and policymakers: The agency's prior additions of exploited ScreenConnect vulnerabilities to its catalog indicate federal attention. Continued monitoring and public advisories will remain a key mechanism for tracking exploitation and informing defenders.

ConnectWise's immediate ask is straightforward: apply the scoped-permission changes now and await the vendor patch later this week. What remains unsettled is the true scale of exposure — Shadowserver reports nearly 6,000 instances visible on the internet, but there is no public accounting of how many of those systems remain vulnerable, have been hardened, or are decoys. Given the product's exploitation history by both financially motivated ransomware groups and state-backed actors, administrators and service providers face an urgent set of operational decisions in the coming days.

Original story on BleepingComputer