ConnectWise has issued a warning regarding a newly identified vulnerability in its ScreenConnect remote access platform, affecting both cloud and on-premises deployments. The company has not yet assigned a CVE ID to this flaw but has provided temporary mitigation steps while it develops a permanent patch, expected later this week.
The security issue specifically concerns the file transfer behavior within ScreenConnect Remote Access Support and Access sessions. ScreenConnect is widely utilized by managed service providers (MSPs), IT departments, and support teams for various tasks including troubleshooting, system maintenance, and patching.
To mitigate potential attacks, ConnectWise advises IT administrators to log into their ScreenConnect Administration page, navigate to Security Roles, and edit user roles. Within the Scoped Permissions window for each session group, administrators should deselect the "TransferFiles" permission (or "TransferFilesInSession" for legacy configurations) and save the changes. This process must be repeated for all roles.
This advisory comes as nearly 6,000 ScreenConnect instances are currently tracked as exposed online by the internet security watchdog Shadowserver. It remains unclear how many of these are honeypots or have implemented the recommended security measures.
ScreenConnect vulnerabilities have historically been targeted by various threat actors, including financially motivated groups and state-sponsored entities. For instance, in 2024, ransomware gangs and the North Korean APT group Kimsuky exploited a different ScreenConnect flaw, CVE-2024-1709, to deploy malware. Last year, ConnectWise disclosed that suspected state-sponsored hackers breached its systems via a high-severity ViewState code injection bug, CVE-2025-3935, gaining access to a limited number of cloud-based customer instances.
Earlier this year, in March, ConnectWise also addressed CVE-2026-3564, a cryptographic signature verification vulnerability in ScreenConnect that could allow attackers to hijack unpatched instances. Since February 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three ScreenConnect vulnerabilities to its catalog of actively exploited flaws, with two of these having been leveraged in ransomware attacks.






