492/69 Tuesday, September 8, 2026
ConnectWise has issued a security advisory for ScreenConnect Remote Access related to file transfer behavior within Support and Access sessions. The issue affects both Cloud and On-Premise deployments. At this time, no CVE identifier has been assigned to the vulnerability, and an official patch is still under development. However, ConnectWise has published temporary mitigation measures that administrators can apply immediately.
ConnectWise has not yet disclosed technical details about the root cause of the issue, the conditions required for exploitation, or the potential impact if it is successfully exploited. The confirmed information is that the issue affects file transfers in ScreenConnect Remote Access Support and Access sessions. Therefore, it is not yet possible to determine what type of impact the vulnerability may lead to. In addition, Shadowserver has detected nearly 6,000 ScreenConnect instances exposed to the internet, but it remains unclear how many of these are honeypots or already have protective measures in place.
While no official patch is available, administrators should follow ConnectWise’s temporary mitigation guidance by navigating to Administration > Security > Roles, editing user roles, and reviewing the session groups that have assigned permissions. Under Scoped Permissions, administrators should remove the TransferFiles permission, or TransferFilesInSession for legacy systems, for each session group. They should then save the changes and repeat the process for all relevant roles. Administrators should also continue monitoring ConnectWise advisories and apply the official patch once it is released.
