ConnectWise has released temporary mitigation guidance for a newly identified ScreenConnect remote access vulnerability and says a permanent security update is expected later this week.
ScreenConnect is a remote access and support platform available in both cloud-hosted and on-premises versions. Managed service providers (MSPs), IT departments, and technical support teams commonly use it for troubleshooting, software patching, file transfers, and system maintenance.
The newly disclosed security issue affects both cloud and on-premises ScreenConnect deployments. ConnectWise has not yet assigned a CVE identifier, which means the vulnerability cannot currently be tracked through the standard vulnerability database.
“ConnectWise has identified an issue impacting ScreenConnect® remote access support and file transfer behavior in access sessions,” the company said in a security advisory issued Thursday.
Until the permanent patch is available, ConnectWise recommends disabling the affected file-transfer permission to reduce the risk of exploitation. ScreenConnect administrators should apply the following temporary mitigation steps:
- Log in to the ScreenConnect management console.
- Go to Administration > Security > Roles.
- Edit each user role and review the session groups assigned to that role.
- In the Scoped Permissions window, clear the TransferFiles permission. For legacy deployments, clear TransferFilesInSession for each session group.
- Save the changes and repeat the process for every role.
Internet security monitoring organization Shadowserver is currently tracking approximately 6,000 ScreenConnect instances exposed to the internet. It is not yet known how many of those systems are honeypots, protected by access controls, or already secured by administrators.

ScreenConnect vulnerabilities have repeatedly been targeted by financially motivated cybercriminals and state-sponsored hacking groups, making it important for organizations to apply the mitigation as soon as possible.
In 2024, a ransomware group and the North Korean Kimsuky advanced persistent threat (APT) group exploited another ScreenConnect vulnerability, tracked as CVE-2024-1709, to compromise vulnerable systems and deploy malware.
ConnectWise also reported last year that suspected state-sponsored attackers had compromised its systems through a high-severity ViewState code-injection vulnerability, CVE-2025-3935. The incident potentially exposed a limited number of customer cloud instances.
Earlier this year, ConnectWise addressed a ScreenConnect cryptographic signature-verification vulnerability tracked as CVE-2026-3564. An attacker could potentially use the flaw to hijack an unpatched ScreenConnect instance.
Since February 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included three ScreenConnect vulnerabilities in its Known Exploited Vulnerabilities (KEV) Catalog. Two of those flaws have also been exploited in ransomware attacks.
Overall prevention scores can obscure what happens after an attacker gains initial access. When threat actors use valid credentials, the effectiveness of security defenses can drop sharply.
The Blue Report 2026 evaluates defensive techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com



