ConnectWise: ConnectWise ScreenConnect vulnerability allows unauthorized file transfers

ConnectWise: ConnectWise ScreenConnect vulnerability allows unauthorized file transfers

ConnectWise Warns of Critical File-Transfer Vulnerability in ScreenConnect

ConnectWise has issued a security advisory for an undisclosed file-transfer vulnerability affecting both cloud-hosted and on-premises deployments of its ScreenConnect remote access platform. The flaw, which remains under investigation, could allow threat actors to transfer malicious or sensitive files during remote support sessions posing a significant risk given the platform’s privileged access to customer environments.

While technical details are not yet public, the company has urged organizations to immediately remove file-transfer permissions from technician roles as a temporary mitigation. A permanent fix and a CVE assignment are pending.

The vulnerability is particularly concerning due to ScreenConnect’s widespread use in enterprise environments. Shadowserver reports nearly 6,000 internet-exposed instances, increasing the potential for exploitation. Past ScreenConnect flaws have been exploited by ransomware groups and state-sponsored actors, raising concerns about opportunistic attacks if the issue is not addressed swiftly.

Organizations using ScreenConnect are advised to apply the recommended mitigations until a patch is released.

Source: https://www.msspalert.com/brief/connectwise-screenconnect-vulnerability-allows-unauthorized-file-transfers

ConnectWise TPRM report: https://www.rankiteo.com/company/connectwise

"id": "con1789489782",
"linkid": "connectwise",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Organizations using '
                                              'ScreenConnect (nearly 6,000 '
                                              'internet-exposed instances)',
                        'industry': 'Technology (Remote Access Software)',
                        'name': 'ConnectWise',
                        'type': 'Vendor'}],
 'attack_vector': 'File-transfer during remote support sessions',
 'customer_advisories': 'Security advisory issued to customers with mitigation '
                        'steps.',
 'description': 'ConnectWise has issued a security advisory for an undisclosed '
                'file-transfer vulnerability affecting both cloud-hosted and '
                'on-premises deployments of its ScreenConnect remote access '
                'platform. The flaw could allow threat actors to transfer '
                'malicious or sensitive files during remote support sessions, '
                'posing a significant risk given the platform’s privileged '
                'access to customer environments.',
 'impact': {'operational_impact': 'Privileged access to customer environments '
                                  'at risk',
            'systems_affected': 'ScreenConnect remote access platform '
                                '(cloud-hosted and on-premises)'},
 'investigation_status': 'Ongoing',
 'recommendations': 'Organizations using ScreenConnect are advised to apply '
                    'the recommended mitigations (remove file-transfer '
                    'permissions) until a patch is released.',
 'references': [{'source': 'ConnectWise Security Advisory'},
                {'source': 'Shadowserver'}],
 'response': {'communication_strategy': 'Security advisory issued to customers',
              'containment_measures': 'Remove file-transfer permissions from '
                                      'technician roles as a temporary '
                                      'mitigation',
              'remediation_measures': 'Permanent fix and CVE assignment '
                                      'pending'},
 'threat_actor': ['Ransomware groups', 'State-sponsored actors'],
 'title': 'Critical File-Transfer Vulnerability in ConnectWise ScreenConnect',
 'type': 'Vulnerability',
 'vulnerability_exploited': 'Undisclosed file-transfer vulnerability'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.