ConnectWise warns of new ScreenConnect flaw without patch

A Critical Vulnerability in ScreenConnect Exposes Thousands of Systems to Attack

ConnectWise, a leading provider of IT management software, has identified a security flaw in its popular remote access platform, ScreenConnect. The vulnerability allows attackers to exploit file transfer behavior in support and access sessions, potentially giving them unauthorized access to sensitive data. What’s more alarming is that this issue affects both cloud and on-premises deployments, and no patch is available yet.

The vulnerability was discovered by ConnectWise itself, which has taken the initiative to provide temporary mitigation measures until a permanent fix can be released later this week. To implement these temporary fixes, IT administrators must navigate to the ScreenConnect Administration page, edit user roles, and check session groups with assigned permissions. From there, they must deselect the TransferFiles permission for each group, saving changes and repeating the process for all roles.

This issue is particularly concerning given that nearly 6,000 ScreenConnect instances are currently exposed online, according to the Internet security watchdog Shadowserver. While it’s unclear how many of these systems have already been secured or are honeypots (decoy targets designed to attract attackers), it’s evident that the threat landscape surrounding ScreenConnect is growing. In fact, this vulnerability has all the makings of a highly coveted target for financially motivated and state-backed hacking groups.

As we’ve seen before, ScreenConnect vulnerabilities have been exploited in the wild by notorious actors like ransomware gangs and the Kimsuky North Korean APT hacking group. In 2024, these groups dropped malware on vulnerable systems via another ScreenConnect flaw (CVE-2024-1709). More recently, ConnectWise disclosed that suspected state-sponsored hackers breached its systems via a high-severity ViewState code injection bug (CVE-2025-3935), gaining access to cloud-based instances of some customers.

The sheer number of ScreenConnect vulnerabilities being actively exploited is staggering. Since February 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three ScreenConnect flaws to its catalog of actively exploited weaknesses, two of which were abused in ransomware attacks. This highlights the importance of staying up-to-date with security patches and monitoring systems for potential threats.

To mitigate this vulnerability, IT administrators must prioritize implementing temporary fixes and keeping a close eye on their ScreenConnect instances. In the long run, it’s essential to ensure that all systems are patched regularly and that users have valid credentials to prevent exploitation. As we’ve seen time and time again, prevention is key, but even with robust defenses in place, attackers can still find ways to breach systems once they gain initial access.

In light of this vulnerability, we recommend that IT administrators review their ScreenConnect configurations immediately and follow ConnectWise’s temporary mitigation steps to minimize the risk of exploitation. By taking proactive measures now, organizations can reduce the likelihood of falling victim to attacks and protect sensitive data from unauthorized access.


Source: Bleeping Computer — 2026-09-07