High
ConnectWise, ScreenConnect, RMM, Remote Access, Vulnerability, MSP Security, CISA KEV

ConnectWise ScreenConnect: Unpatched File-Transfer Flaw
ConnectWise disclosed a new, still-unpatched ScreenConnect vulnerability in file-transfer behavior affecting cloud and on-premises. A fix is due this week; apply mitigations now.
ConnectWise has disclosed a new, still-unpatched ScreenConnect vulnerability affecting file-transfer behavior in Remote Access Support and Access sessions, and it has released temporary mitigation steps while a permanent fix is expected later this week. The flaw affects both cloud and on-premises deployments and has not yet received a CVE identifier. ScreenConnect is a remote-access platform used heavily by managed service providers, IT departments, and support teams, which makes any unpatched flaw in it a high-value target. ConnectWise issued the advisory and asked administrators to apply the interim mitigation immediately.
Internet-monitoring group Shadowserver currently tracks nearly 6,000 ScreenConnect instances exposed online, though it is not known how many are honeypots or already secured. The exposure matters because ScreenConnect has a long history of being attacked. In 2024, ransomware gangs and the North Korean APT group Kimsuky exploited CVE-2024-1709 to drop malware, and in 2025 suspected state-sponsored hackers breached ConnectWise itself through a ViewState code-injection flaw, CVE-2025-3935, reaching a limited number of cloud customers. In March 2026, ConnectWise fixed a cryptographic signature-verification flaw, CVE-2026-3564, that could let attackers hijack unpatched instances.
Since February 2024, CISA has added three ScreenConnect vulnerabilities to its Known Exploited Vulnerabilities catalog, two of which were also abused in ransomware attacks. That track record is why defenders should treat a new, unpatched ScreenConnect flaw as a when-not-if target and act on the mitigation before the patch arrives.
What should ScreenConnect admins do before the patch?
Apply ConnectWise's published interim mitigation for the file-transfer issue immediately, on both cloud and on-premises instances, then patch as soon as the fix ships later this week. Because no CVE or indicators exist yet, reduce exposure by restricting who can reach the ScreenConnect console, keeping it off the open internet where possible, and monitoring session and file-transfer activity for anomalies in the meantime.
Why are remote-access tools targeted so often?
Because they are designed for exactly what an attacker wants: remote control of many machines from one console, with legitimate-looking traffic. Compromising a ScreenConnect server or tenant can hand an intruder the same reach a support team has across every connected endpoint, which is why both financially motivated and state-backed groups repeatedly go after these platforms. The leverage, not any single bug, is what makes them a durable target.
Detail | Value |
|---|---|
Product | ConnectWise ScreenConnect (cloud and on-premises) |
Flaw | File-transfer behavior in Remote Access sessions |
CVE | None assigned yet |
Patch | Expected later the week of September 7, 2026 |
Interim | Vendor mitigation steps published in advisory |
Exposure | ~6,000 instances exposed online (Shadowserver) |
Our read
ScreenConnect sits in the same high-leverage category as other RMM and remote-access platforms: own the console, and you inherit its reach across every managed machine. With three prior ScreenConnect flaws already in CISA KEV and two used in ransomware, the base rate for eventual exploitation of a new, unpatched issue is high enough that waiting for a CVE is the wrong call. The defensible posture is to apply the interim mitigation now, keep the console off the public internet, and verify from the outside that it is not reachable by untrusted networks before the fix lands.
Reporting by BleepingComputer; advisory and mitigation per ConnectWise; exposure figures per Shadowserver. Sources linked above.
Related: What is a software supply chain attack? and What is CISA KEV?.