TechNewsReel
Live

ConnectWise Warns of ScreenConnect File Transfer Flaw With No Immediate Patch

Administrators must manually disable file transfer permissions to mitigate a new vulnerability affecting cloud and on-premises deployments.

TechNewsReel Newsroom · September 7, 2026

ConnectWise has issued a security advisory for a vulnerability in ScreenConnect Remote Access that allows improper file transfer behavior. The flaw affects both cloud and on-premises deployments, leaving a wide array of IT environments potentially exposed.

The vulnerability specifically impacts file transfer behavior during Support and Access sessions. While the risk is active, ConnectWise has not yet released an official CVE ID or a permanent software patch. To protect systems, administrators must implement a temporary mitigation by deselecting 'TransferFiles'—or 'TransferFilesInSession' for legacy versions—within the Scoped Permissions window for all user roles.

A Pattern of Critical Flaws

ScreenConnect is a cornerstone tool for managed service providers (MSPs) and internal IT departments, but it has become a frequent target for sophisticated attackers. The platform has a documented history of critical security failures, including CVE-2024-1709, an authentication bypass, and CVE-2026-3564, which involved cryptographic signature verification.

These previous vulnerabilities have been leveraged by state-backed actors and various ransomware gangs. The severity of these recurring issues is underscored by the Cybersecurity and Infrastructure Security Agency (CISA), which has previously added three separate ScreenConnect flaws to its catalog of known exploited vulnerabilities.

Supply-Chain Implications

The current vulnerability is particularly concerning due to the role ScreenConnect plays in the IT supply chain. Because MSPs use the software to manage hundreds of downstream clients simultaneously, a single flaw in the platform can create a massive ripple effect, granting attackers a gateway into numerous corporate networks.

The lack of an immediate patch increases this risk, as it forces administrators to manually audit and adjust permissions across all user roles to prevent the exploitation of file transfer capabilities. This manual requirement introduces a window of opportunity for attackers to strike before all instances are secured.

The Scale of Exposure

The potential attack surface remains significant. Data from Shadowserver indicates that nearly 6,000 ScreenConnect instances are currently exposed online, providing a visible map for threat actors seeking to exploit the file transfer flaw. Security teams are advised to monitor their instances closely and apply the recommended permission changes immediately while awaiting a formal update from ConnectWise.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.