ConnectWise Issues Urgent Mitigation for New ScreenConnect Vulnerability
A new vulnerability affecting **ConnectWise ScreenConnect** remote access software has prompted the company to release temporary mitigation steps ahead of a full patch. The flaw, which impacts file transfer behavior in both cloud and on-premises deployments, poses a significant risk given **ScreenConnect**'s history as a target for both financially motivated and state-backed threat actors.
ConnectWise has alerted users to a newly discovered vulnerability within its **ScreenConnect** remote access platform, widely utilized by managed service providers (MSPs), IT departments, and support teams. The as-yet unassigned **CVE** flaw specifically affects file transfer functionality during **ScreenConnect** Remote Access Support and Access sessions.
### Temporary Mitigations Released
While **ConnectWise** is actively developing a permanent fix, it has provided immediate mitigation steps for IT administrators to implement. These measures are designed to preemptively block potential attacks leveraging the vulnerability.
Administrators should follow these steps:
1. Log in to the **ScreenConnect** Administration page.
2. Navigate to Administration > Security > Roles.
3. Edit user roles and identify session groups with assigned permissions.
4. In the Scoped Permissions window, deselect the `TransferFiles` permission (or `TransferFilesInSession` for legacy systems) for each session group.
5. Save changes and repeat for all relevant roles.
### Widespread Exposure and Past Exploits
The internet security watchdog **Shadowserver** currently tracks nearly 6,000 **ScreenConnect** instances exposed online. While it's unclear how many of these are honeypots or have been secured, the sheer number underscores the potential attack surface.

**ScreenConnect** vulnerabilities have historically been high-value targets for various threat groups. In 2024, ransomware gangs and the North Korean APT group **Kimsuky** notably exploited a different **ScreenConnect** flaw (**CVE-2024-1709**) to deploy malware on compromised systems.
Last year, **ConnectWise** itself disclosed a breach by suspected state-sponsored hackers who exploited a high-severity **ViewState** code injection bug (**CVE-2025-3935**), gaining access to cloud-based instances of a limited number of customers.
More recently, in March of this year, **ConnectWise** patched a cryptographic signature verification vulnerability (**CVE-2026-3564**) that could have allowed attackers to hijack unpatched instances.
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has, since February 2024, added three **ScreenConnect** vulnerabilities to its catalog of actively exploited flaws, with two of these having been leveraged in ransomware attacks.