A critical vulnerability has been discovered in ConnectWise’s ScreenConnect remote access platform, leaving millions of systems exposed to potential attacks. The security flaw affects both cloud and on-premises deployments of ScreenConnect, which is widely used by managed service providers (MSPs), IT departments, and support teams for troubleshooting, patching, and system maintenance.
The vulnerability allows attackers to manipulate file transfer behavior within ScreenConnect sessions, potentially leading to unauthorized access or data exfiltration. ConnectWise has acknowledged the issue but notes that it does not yet have a permanent fix in place, instead offering temporary mitigation steps to help block potential attacks. These measures require IT administrators to edit user roles and permissions on the ScreenConnect Administration page, effectively disabling file transfer capabilities for all session groups.
The impact of this vulnerability is significant, given the widespread adoption of ScreenConnect across various industries. Shadowserver estimates that nearly 6,000 instances are exposed online, although it’s unclear how many have already been secured or are honeypots designed to attract malicious activity. This situation is particularly concerning considering the history of ScreenConnect vulnerabilities being targeted by financially motivated and state-backed hacking groups.
In recent years, we’ve seen numerous high-profile attacks leveraging ScreenConnect flaws. For instance, in 2024, ransomware gangs and North Korea’s Kimsuky APT exploited a different vulnerability (CVE-2024-1709) to drop malware on vulnerable systems. ConnectWise itself faced a breach last year via a ViewState code injection bug (CVE-2025-3935), which provided access to the cloud-based instances of some customers.
This latest development highlights the importance of staying vigilant and up-to-date with security patches, especially for widely used platforms like ScreenConnect. As we’ve seen, even when vulnerabilities are disclosed, attackers can still find ways to exploit them if they’re not patched in a timely manner.
For those affected by this vulnerability, it’s essential to implement the temporary mitigation steps provided by ConnectWise as soon as possible. This will help block potential attacks until a permanent fix is available. Moreover, this incident serves as a reminder of the critical importance of regular security audits and patch management practices to prevent similar vulnerabilities from being exploited in the future.
Practically speaking, IT administrators should prioritize reviewing their ScreenConnect configurations and implementing additional security measures to minimize the risk of unauthorized access or data breaches. This includes conducting thorough vulnerability assessments, ensuring that all systems are up-to-date with the latest patches, and regularly monitoring for suspicious activity. By taking proactive steps to address this vulnerability, organizations can reduce their exposure to potential attacks and maintain a stronger overall cybersecurity posture.
Source: Bleeping Computer — 2026-09-07