ConnectWise warns of an unpatched ScreenConnect flaw and tells admins to disable file transfers

ConnectWise says a newly identified ScreenConnect security flaw could affect both cloud and on-premises customers, and no patch is available yet. The issue affects file transfer behavior in ScreenConnect Remote Access Support and Access sessions and has not yet been assigned a CVE ID. As a temporary mitigation, admins are told to remove the TransferFiles or legacy TransferFilesInSession permission from all relevant roles and session groups.
Why it matters: Organizations and managed service providers that rely on ScreenConnect may need to change settings now to reduce risk until a fix ships later this week. Because remote-support tools are frequently targeted by ransomware and espionage groups, internet-exposed instances deserve urgent review.

Sources

Modified ScreenConnect Clients Used in Worm-Like Campaign
Ionut Arghire 2026.09.07 95% relevant
This article provides the attack detail behind ConnectWise's advisory, describing a live worm-like campaign in which socially engineered victims install rogue ScreenConnect clients that abuse file transfer behavior to deploy VBScript and PowerShell payloads, establish persistence, install UltraViewer, and propagate to newly connected endpoints.
ConnectWise warns of new ScreenConnect flaw without patch
Sergiu Gatlan 2026.09.07 100% relevant
This article establishes a distinct new event: a newly disclosed, currently unpatched ScreenConnect vulnerability with vendor-issued mitigations, not the earlier ScreenConnect CVE-2026-3564 or older exploited flaws.
← Back to all stories