ConnectWise Warns of Critical ScreenConnect Vulnerability Exposing Users
ConnectWise has issued temporary countermeasures for a newly discovered vulnerability in the ScreenConnect Remote Access platform, which remains unpatched as of now.
Vulnerability Overview
ScreenConnect serves as a remote access solution deployed either on-premises or in cloud environments, commonly utilized by managed service providers (MSPs), IT departments, and support teams for tasks such as troubleshooting, system updates, and maintenance. The flaw impacts both cloud-based and on-premises implementations and has not yet been assigned a CVE identifier for standardized tracking.
Flaw Details and Impact
While a permanent fix is pending, ConnectWise has outlined specific steps for IT administrators to mitigate risks. These include accessing the ScreenConnect Administration portal, navigating to Administration > Security > Roles, and modifying user roles to revoke TransferFiles permissions for relevant session groups. Legacy systems may require adjustments to TransferFilesInSession settings. Each role must be reviewed and updated individually.
Shadowserver Monitoring
Shadowserver, an independent cybersecurity monitoring organization, has identified approximately 6,000 publicly accessible ScreenConnect instances. However, the exact number of these systems that are honeypots or already secured remains undisclosed.
Historical Exploitation
Historically, exposed ScreenConnect deployments have attracted exploitation by both financially motivated actors and state-sponsored threat groups. For example, in 2024, ransomware operators and the Kimsuky APT group leveraged a separate ScreenConnect vulnerability (CVE-2024-1709) to deploy malicious payloads. Earlier this year, ConnectWise addressed another critical flaw (CVE-2026-3564) that allowed attackers to compromise unpatched instances through cryptographic signature verification bypasses.
Blue Report Insights
Since February 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed three ScreenConnect vulnerabilities in its actively exploited flaws catalog, with two of these being linked to ransomware campaigns. Data from the Blue Report 2026 highlights that 37% of attacker activities are blocked when valid credentials are present, underscoring the importance of layered defense strategies. The report analyzed 338 million simulations across customer environments to evaluate defensive effectiveness.
Technical Details and Recommendations
Technical details surrounding the current flaw remain limited, but the lack of a CVE identifier suggests it is either newly disclosed or under active investigation. Organizations using ScreenConnect are advised to implement the recommended mitigations immediately while awaiting a permanent resolution.
