ConnectWise Warns of Critical File-Transfer Vulnerability in ScreenConnect
ConnectWise has issued a security advisory for an undisclosed file-transfer vulnerability affecting both cloud-hosted and on-premises deployments of its ScreenConnect remote access platform. The flaw, which remains under investigation, could allow threat actors to transfer malicious or sensitive files during remote support sessions posing a significant risk given the platform’s privileged access to customer environments.
While technical details are not yet public, the company has urged organizations to immediately remove file-transfer permissions from technician roles as a temporary mitigation. A permanent fix and a CVE assignment are pending.
The vulnerability is particularly concerning due to ScreenConnect’s widespread use in enterprise environments. Shadowserver reports nearly 6,000 internet-exposed instances, increasing the potential for exploitation. Past ScreenConnect flaws have been exploited by ransomware groups and state-sponsored actors, raising concerns about opportunistic attacks if the issue is not addressed swiftly.
Organizations using ScreenConnect are advised to apply the recommended mitigations until a patch is released.
ConnectWise TPRM report: https://www.rankiteo.com/company/connectwise
"id": "con1789489782",
"linkid": "connectwise",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Organizations using '
'ScreenConnect (nearly 6,000 '
'internet-exposed instances)',
'industry': 'Technology (Remote Access Software)',
'name': 'ConnectWise',
'type': 'Vendor'}],
'attack_vector': 'File-transfer during remote support sessions',
'customer_advisories': 'Security advisory issued to customers with mitigation '
'steps.',
'description': 'ConnectWise has issued a security advisory for an undisclosed '
'file-transfer vulnerability affecting both cloud-hosted and '
'on-premises deployments of its ScreenConnect remote access '
'platform. The flaw could allow threat actors to transfer '
'malicious or sensitive files during remote support sessions, '
'posing a significant risk given the platform’s privileged '
'access to customer environments.',
'impact': {'operational_impact': 'Privileged access to customer environments '
'at risk',
'systems_affected': 'ScreenConnect remote access platform '
'(cloud-hosted and on-premises)'},
'investigation_status': 'Ongoing',
'recommendations': 'Organizations using ScreenConnect are advised to apply '
'the recommended mitigations (remove file-transfer '
'permissions) until a patch is released.',
'references': [{'source': 'ConnectWise Security Advisory'},
{'source': 'Shadowserver'}],
'response': {'communication_strategy': 'Security advisory issued to customers',
'containment_measures': 'Remove file-transfer permissions from '
'technician roles as a temporary '
'mitigation',
'remediation_measures': 'Permanent fix and CVE assignment '
'pending'},
'threat_actor': ['Ransomware groups', 'State-sponsored actors'],
'title': 'Critical File-Transfer Vulnerability in ConnectWise ScreenConnect',
'type': 'Vulnerability',
'vulnerability_exploited': 'Undisclosed file-transfer vulnerability'}