← Terug naar overzicht

ConnectWise has disclosed a new vulnerability affecting its ScreenConnect remote access software. The flaw does not yet have a patch available, though ConnectWise has shared temporary mitigation measures for affected users. A patch is planned for release later in the week. ScreenConnect is widely used in enterprise environments for remote support and access, making vulnerabilities in it high-impact targets. The lack of an immediate patch increases the risk window for exploitation. Organizations using ScreenConnect are advised to apply the temporary mitigations as soon as possible. This follows a pattern of prior high-severity vulnerabilities in ScreenConnect that were actively exploited by threat actors. The article serves as an early warning advisory for administrators to act before a formal fix is released.

Technical details

ConnectWise identified a security vulnerability affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions. The flaw impacts both cloud-hosted and on-premises deployments of ScreenConnect. At the time of disclosure, no CVE ID had been assigned and no patch was available; ConnectWise indicated a permanent fix was planned for later in the same week. The vulnerability relates to the TransferFiles (or TransferFilesInSession for legacy) permission within ScreenConnect session groups. Approximately 6,000 ScreenConnect instances were observed exposed to the internet by Shadowserver at the time of reporting. Historically, ScreenConnect vulnerabilities have been exploited by financially motivated threat actors (e.g., ransomware gangs) and state-sponsored APT groups.

Mitigation steps

Apply the following temporary mitigation steps until a patch is available: 1) Log in to the ScreenConnect Administration page. 2) Navigate to Administration > Security > Roles. 3) Edit user roles and review session groups (shown in bold) with permissions assigned to them. 4) In the Scoped Permissions window, deselect the 'TransferFiles' permission (or 'TransferFilesInSession' for legacy versions) for each session group. 5) Save changes and repeat for all roles. Monitor ConnectWise security advisories for the release of a permanent patch. Ensure internet-exposed ScreenConnect instances are minimized and monitor Shadowserver dashboards for exposure tracking. Apply patches for previously disclosed CVEs (CVE-2024-1709, CVE-2025-3935, CVE-2026-3564) if not already done.

Affected products

  • ConnectWise ScreenConnect (cloud-hosted deployments)
  • ConnectWise ScreenConnect (on-premises deployments)

Related CVE's

  • CVE-2024-1709
  • CVE-2025-3935
  • CVE-2026-3564

Related threat actors

  • Kimsuky (North Korean APT)
  • Ransomware gangs (financially motivated
  • Suspected state-sponsored hackers (unspecified)
  • unspecified)

Categories

  • Enterprise Applications
  • Security Tools
  • Zero-Day Vulnerabilities