ConnectWise warned of a new security vulnerability in the ScreenConnect Remote Access platform, confirming that the flaw affects file-transfer behavior within Support and Access sessions. The issue affects on-premises deployments of the platform and cloud-hosted services, while the vulnerability has not yet been assigned a CVE number to facilitate tracking through vulnerability databases.
The company has not yet released the final patch, but said it is working on a permanent fix and expects to release it later this week. Until it becomes available, ConnectWise published a temporary measure intended to reduce the chances of exploitation by removing file-transfer permissions from session groups.
Proposed Temporary Measure
IT administrators should log in to the ScreenConnect management page, then navigate to Administration > Security > Roles. They should then edit user roles and review the session groups that appear in bold and have specific permissions.
Within the Scoped Permissions window, the company recommends deselecting the TransferFiles permission for each session group. In environments that use the legacy permission, administrators should deselect TransferFilesInSession instead. After saving the changes, the process should be repeated for all relevant roles.
Why Does This Matter?
ScreenConnect is used by managed service providers, IT teams, and technical support teams to remotely access systems for troubleshooting, applying updates, and performing maintenance work. Therefore, file-transfer permissions are not a peripheral feature, and exploiting a flaw associated with them could affect support operations or enable unauthorized file transfers, depending on how roles and sessions are configured in each environment.
The warning is particularly important because of the potential scale of exposure and the platform’s history of targeting. Shadowserver is monitoring approximately 6,000 exposed ScreenConnect instances on the internet, although no data is available to determine how many systems are honeypots or have already been secured. The article also indicates that ScreenConnect vulnerabilities have previously been exploited by cyber-extortion groups and state-backed actors.
A Recurring Security Context
In 2024, ransomware gangs and the North Korean Kimsuky group exploited another ScreenConnect vulnerability, CVE-2024-1709, to deploy malware. Last year, ConnectWise disclosed that its systems had been breached through a high-severity ViewState injection vulnerability, CVE-2025-3935, which enabled access to cloud instances belonging to a limited number of customers.
In March of this year, the company addressed a cryptographic signature-validation vulnerability, CVE-2026-3564, which could have allowed the hijacking of unpatched instances. Since February 2024, the U.S. Cybersecurity and Infrastructure Security Agency, CISA, has added three ScreenConnect vulnerabilities to its Known Exploited Vulnerabilities Catalog; two of them were also used in ransomware attacks.
In practice, the temporary measure is not a substitute for the final patch, and the absence of a CVE number may make it more difficult to standardize monitoring and coordination between security teams. Organizations using ScreenConnect should review the affected roles and immediately restrict file transfers, then monitor ConnectWise’s update to verify that the flaw has been addressed when it is released.