← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

ConnectWise warns of new ScreenConnect vulnerability, provides temporary mitigations

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • New ScreenConnect vulnerability affects file transfer behavior.
  • Temporary mitigation steps provided; patch expected later this week.
  • Vulnerability impacts both cloud and on-premises deployments.
  • Previous ScreenConnect flaws have been exploited by threat actors.

New ScreenConnect Vulnerability Identified

ConnectWise has disclosed a new security vulnerability within its ScreenConnect Remote Access platform. The flaw specifically impacts file transfer behavior during Support and Access sessions. This issue affects both cloud-hosted and on-premises deployments of ScreenConnect, a tool widely utilized by managed service providers (MSPs), IT departments, and support teams for various tasks including troubleshooting and system maintenance. A CVE ID for this vulnerability has not yet been assigned.

Temporary Mitigations Available

While ConnectWise is developing a permanent fix, which is anticipated to be released later this week, it has provided immediate mitigation steps. These steps involve IT administrators logging into the ScreenConnect Administration page, navigating to Security > Roles, and editing user roles. Within the Scoped Permissions window, administrators must deselect the 'TransferFiles' permission (or 'TransferFilesInSession' for legacy systems) for each session group and save the changes. This process needs to be repeated for all relevant roles to help block potential attacks.

Context of Previous Exploitations

The discovery of this new vulnerability is particularly concerning given the history of ScreenConnect flaws being targeted in the wild. In 2024, a different ScreenConnect vulnerability (CVE-2024-1709) was exploited by ransomware groups and the Kimsuky North Korean APT group to deploy malware. Last year, ConnectWise also reported a breach via a ViewState code injection bug (CVE-2025-3935) that affected a limited number of cloud-based customer instances. Earlier this year, another cryptographic signature verification vulnerability (CVE-2026-3564) was addressed, which could have allowed attackers to hijack unpatched instances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three ScreenConnect vulnerabilities to its list of actively exploited flaws since February 2024, with two of these being used in ransomware attacks.

Widespread Exposure

Internet security watchdog Shadowserver currently monitors nearly 6,000 ScreenConnect instances that are exposed online. The exact number of vulnerable systems or honeypots among these exposed instances is not specified. The widespread use of ScreenConnect makes any vulnerability a significant concern for the broader IT and cybersecurity community.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~8 min · 6 stories · Sep 07

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

ConnectWise issued a security advisory regarding a new vulnerability in its ScreenConnect Remote Access platform that affects file transfer behavior. While a permanent patch is expected later this week, the company has provided temporary mitigation steps for administrators to implement. This vulnerability is significant because ScreenConnect is widely used by IT professionals, and previous flaws in the platform have been actively exploited by threat actors, including ransomware gangs and state-backed groups.